Description
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Remediation
References
https://github.com/primefaces/primefaces/issues/5642
Related Vulnerabilities
CVE-2023-39154 Vulnerability in maven package com.qualys.plugins:qualys-was
CVE-2020-10244 Vulnerability in maven package dev.paseto:jpaseto-sodium
CVE-2020-7663 Vulnerability in npm package websocket-extensions
CVE-2019-16943 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-8331 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap