Description
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Remediation
References
https://github.com/primefaces/primefaces/issues/5642
Related Vulnerabilities
CVE-2019-10241 Vulnerability in maven package org.eclipse.jetty:jetty-util
CVE-2020-2291 Vulnerability in maven package org.jenkins-ci.plugins:couchdb-statistics
CVE-2016-10735 Vulnerability in maven package li.rudin.mavenjs:bootstrap
CVE-2023-49486 Vulnerability in maven package com.jfinal:jfinal
CVE-2021-23356 Vulnerability in npm package kill-process-by-name