CVE-2021-36738
06.01.2022, 09:15
The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact
| Vendor | Product | Version |
|---|---|---|
| apache | pluto | 𝑥 < 3.1.1 |
𝑥
= Vulnerable software versions