CVE-2019-0186
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XS
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: Uninstall the ChatRoomDemo war file - or - migrate to version 3.1.0 of the chat-room-demo war file.
MEDIUM · CVSS 6.1
EPSS 0.05755
Schedule remediation
- EPSS percentile: top 9% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0