Description
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Remediation
References
https://github.com/primefaces/primefaces/issues/5642
Related Vulnerabilities
CVE-2017-12621 Vulnerability in maven package commons-jelly:commons-jelly
CVE-2020-7766 Vulnerability in maven package org.webjars.npm:json-ptr
CVE-2020-7690 Vulnerability in npm package jspdf
CVE-2017-15010 Vulnerability in npm package tough-cookie
CVE-2017-16026 Vulnerability in maven package org.webjars.npm:request