Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console
Moderate severity
GitHub Reviewed
Published
Jul 16, 2025
to the GitHub Advisory Database
•
Updated Jul 18, 2025
Description
Published by the National Vulnerability Database
Jul 16, 2025
Published to the GitHub Advisory Database
Jul 16, 2025
Reviewed
Jul 18, 2025
Last updated
Jul 18, 2025
In Eclipse GlassFish version 7.0.15, it is possible to perform Reflected Cross-Site Scripting attacks through the Administration Console.
References