Skip to content

Cross Site Scripting (XSS) vulnerability of user input

Moderate
hpehl published GHSA-jhvj-f397-8w6q Jan 16, 2025

Package

maven org.jboss.hal:hal-console (Maven)

Affected versions

< 3.7.7.Final

Patched versions

3.7.7.Final

Description

A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.

Impact

Cross-site scripting (XSS) vulnerability in the management console.

Patches

Fixed in HAL 3.7.7.Final

Workarounds

No workaround available

References

Severity

Moderate

CVE ID

CVE-2025-23366

Weaknesses

No CWEs