Description
Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.
Remediation
References
https://github.com/wocommunity/wonder/pull/992
https://xmit.xyz/security/webobjects-url-tomfoolery/
Related Vulnerabilities
CVE-2023-0871 Vulnerability in maven package org.opennms.core:org.opennms.core.xml
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel-traverse
CVE-2020-35774 Vulnerability in maven package com.twitter:twitter-server
CVE-2022-31943 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2017-18077 Vulnerability in maven package org.webjars.npm:brace-expansion