Description
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Remediation
References
https://github.com/primefaces/primefaces/issues/5642
Related Vulnerabilities
CVE-2021-37712 Vulnerability in npm package tar
CVE-2022-0239 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp
CVE-2020-8203 Vulnerability in maven package org.webjars.bower:lodash
CVE-2022-31170 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2023-38695 Vulnerability in npm package @simonsmith/cypress-image-snapshot