{"id":"CVE-2016-1000273","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-1000273","summary":"Java Melody vulnerable to cross-site scripting","details":"JavaMelody is a monitoring tool for JavaEE applications. Versions prior to 1.61.0 are vulnerable to a cross-site scripting (XSS) attack. This issue was patched in version 1.61.0, and users are recommended to upgrade to the latest version. There are no known workarounds.","published":"2022-07-20T01:36:35Z","modified":"2026-09-10T03:49:44.760738855Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"net.bull.javamelody:javamelody-core","fixedVersion":"1.61.0"}],"fix":{"url":"https://github.com/javamelody/javamelody/commit/e0497c1980acebd257d3da78dfde29ae9bdffdf6","label":"javamelody/javamelody@e0497c1"},"references":[{"type":"WEB","url":"https://github.com/javamelody/javamelody/commit/e0497c1980acebd257d3da78dfde29ae9bdffdf6"},{"type":"PACKAGE","url":"https://github.com/javamelody/javamelody"},{"type":"WEB","url":"https://github.com/javamelody/javamelody/wiki/ReleaseNotes#1620"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:49:44.760738855Z"}}