Payara Platform Payara Server Cross-Site Scripting Vulnerability Allowing Remote Code Inclusion
Vulnerability
A cross-site scripting vulnerability has been identified in Payara Platform Payara Server. This issue allows for improper neutralization of input during web page generation, leading to remote code inclusion. The vulnerability affects Payara Server versions 4.1.2.1919.1 prior to 4.1.2.191.51, 5.20.0 prior to 5.68.0, 6.0.0 prior to 6.23.0, and 6.2022.1 prior to 6.2025.2.
Impact
Exploitation of this vulnerability allows for cross-site scripting, with the potential for remote code inclusion on the affected server.
Reproduction
The vulnerability can be reproduced by injecting malicious scripts into input fields that are not properly sanitized, which can then be executed in the context of the user's browser.
Remediation
Users are advised to update to Payara Server versions 4.1.2.191.51, 5.68.0, 6.23.0, or 6.2025.2.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
