Description
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Remediation
References
https://github.com/primefaces/primefaces/issues/5642
Related Vulnerabilities
CVE-2011-4838 Vulnerability in maven package jruby:jruby
CVE-2018-11788 Vulnerability in maven package org.apache.karaf:org.apache.karaf.util
CVE-2017-5878 Vulnerability in maven package org.red5:red5-server
CVE-2022-31830 Vulnerability in npm package kityminder
CVE-2018-8030 Vulnerability in maven package org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol