Skip to content

CVE-2014-1904

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0181 (1.8%)
Percentil: 82.9%
EPSS: 2026-05-06

Afecta

pivotal_software:spring_framework

Descripción técnica

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

Publicada: 20/3/2014, 16:55:12
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo