JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/java-decompiler/jd-gui/pull/418 | patch |