Description
Cross-site scripting (XSS) vulnerability in ZK Framework before 5.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0101.html
http://secunia.com/advisories/55690
https://github.com/zkoss/zk/blob/v5.0.13/zkdoc/release-note
Related Vulnerabilities
CVE-2023-27987 Vulnerability in maven package org.apache.linkis:linkis-dist
CVE-2021-21380 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ratings-api
CVE-2012-0047 Vulnerability in maven package org.apache.wicket:wicket
CVE-2014-0109 Vulnerability in maven package org.apache.cxf:cxf-api
CVE-2020-5408 Vulnerability in maven package org.springframework.security:spring-security-core