CVE-2019-0186

MEDIUM

Apache Pluto < 3.1.0 - XSS

Title source: rule

Description

The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file

Exploits (1)

exploitdb WRITEUP
by Dhiraj Mishra · textwebappsjava
https://www.exploit-db.com/exploits/46759

Scores

CVSS v3 6.1
EPSS 0.0575
EPSS Percentile 90.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
apache/pluto 3.0.0
apache/pluto 3.0.1
org.apache.portals.pluto/chatRoomDemo 3.0.0 - 3.1.0Maven
Published Apr 26, 2019
Tracked Since Feb 18, 2026