Back

MEDIUM

JSF: XSS due to insufficient escaping of user-supplied content in outputText tags and EL expressions

Published Jul 17, 2014

Description

Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner oracle
Published Jul 17, 2014
Updated Aug 6, 2024
Reserved Sep 18, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Feb 7, 2014
GHSA-3M3R-82GC-53MJ