vendor:
Apache ActiveMQ
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Apache ActiveMQ
Affected Version From: 5.3.2000
Affected Version To: 5.3.2001
Patch Exists: YES
Related CWE: CVE-2010-1582
CPE: a:apache:activemq
Platforms Tested:
2010
Apache ActiveMQ Cross-Site Scripting Vulnerability
The Apache ActiveMQ is prone to a cross-site scripting vulnerability due to improper sanitization of user-supplied input. An attacker can exploit this vulnerability to execute arbitrary script code in the browser of a user visiting the affected site. This can lead to the theft of authentication credentials and enable the attacker to launch further attacks.
Mitigation:
Upgrade to a version higher than 5.3.1 or apply patches provided by the vendor.