{"id":"CVE-2014-5326","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-5326","summary":"Improper Neutralization of Input During Web Page Generation in Direct Web Remoting","details":"Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","published":"2022-05-17T04:21:06Z","modified":"2024-12-07T05:38:42.459059Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.directwebremoting:dwr","fixedVersion":"2.0.11"},{"ecosystem":"Maven","name":"org.directwebremoting:dwr","fixedVersion":"3.0.RC3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5326"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN52422792/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2014-000118"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-07T05:38:42.459059Z"}}