Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web script or HTML via crafted URL, which is not properly handled in a CSS file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2014-12-11T15:00:00

Updated: 2024-08-06T13:03:27.313Z

Reserved: 2014-10-03T00:00:00

Link: CVE-2014-7852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2014-12-11T15:59:00.070

Modified: 2017-01-03T02:59:13.033

Link: CVE-2014-7852

cve-icon Redhat

Severity : Moderate

Publid Date: 2014-12-09T00:00:00Z

Links: CVE-2014-7852 - Bugzilla