MEDIUM 6.1 Maven
JavaScript execution via malicious molfiles (XSS)
GHSA-2pwh-52h7-7j84 · CVE-2024-0758
Published · Modified
Description
Impact
The viewer plugin implementation of <mol:molecule> renders molfile data directly inside a <script> tag without any escaping. Arbitrary JavaScript code can thus be executed in the client browser via crafted molfiles.
Patches
Patched in v0.3.0: Molfile data is now rendered as value of a hidden <input> tag and escaped via JSF's mechanisms.
Workarounds
No workaround available.
Ready to move
Start Securing
Free, no credit card | First findings in minutes