Description
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
Remediation
References
https://github.com/Hurdano/JavaMelody-XSS/wiki/Attack-Vector---JavaMelody
Related Vulnerabilities
CVE-2020-7773 Vulnerability in npm package markdown-it-highlightjs
CVE-2021-32853 Vulnerability in npm package erxes
CVE-2020-7663 Vulnerability in npm package websocket-extensions
CVE-2022-26049 Vulnerability in maven package com.diffplug.gradle:goomph
CVE-2018-15685 Vulnerability in maven package org.webjars.npm:electron