Description
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Remediation
References
https://github.com/primefaces/primefaces/issues/5642
Related Vulnerabilities
CVE-2021-4264 Vulnerability in maven package org.webjars:dustjs-linkedin
CVE-2018-19056 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2012-0392 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-10688 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2021-27290 Vulnerability in maven package org.webjars.npm:ssri