VYPR

Primefaces

by Primetek

CVEs (2)

  • CVE-2017-1000486CriKEVJan 3, 2018
    risk 0.86cvss 9.8epss 0.94

    Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

  • CVE-2020-10544MedMar 13, 2020
    risk 0.33cvss 6.1epss 0.01

    An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.