Description
Railo is an open-source alternative to the popular Coldfusion application server, implementing a FOSSy CFML engine and application server. Multiple critical vulnerabilities were reported in this application server. This test has confirmed a cross-site scripting vulnerability in the administration panel.
Remediation
Upgrade to the latest version of Railo.
References
Related Vulnerabilities
WordPress Plugin Advanced Order Export For WooCommerce Cross-Site Scripting (3.1.3)
WordPress Plugin Custom Dashboard & Login Page-AGCA Cross-Site Scripting (6.9.1)
WordPress Plugin Automated Editor Cross-Site Scripting (1.3)
WordPress Plugin WebEngage Feedback, Survey and Notification Cross-Site Scripting (2.0.0)