Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-4676 Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.
Github GHSA Github GHSA GHSA-p4mx-p49m-8rw4 Improper Neutralization of Input During Web Page Generation in JavaMelody
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-09-17T00:51:25.336Z

Reserved: 2013-06-12T00:00:00Z

Link: CVE-2013-4378

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-09-30T22:55:02.993

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-4378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses