Back

MEDIUM

AS: DOM based XSS in the administration console

Published Nov 26, 2019

Description

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue only affects community JBoss AS 7 prior to 7.1.0 Beta 1. It does not affect components shipped with any Red Hat products.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 26, 2019
Updated Aug 6, 2024
Reserved Sep 21, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Dec 2, 2011