JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/Hurdano/JavaMelody-XSS/wiki/Attack-Vector---JavaMelody | third party advisory exploit |