CVE Database
/

CVE-2021-36739

Back to search

CVE-2021-36739

Published: Jan 6, 2022

Modified: May 22, 2025

PUBLISHED

Description

The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks.

VendorProductVersions

Apache Software Foundation

Apache Portals

affected
org.apache.portals.pluto.archetype:mvcbean-jsp-portlet-archetype 3.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now