Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2020-10544

Disclosure Date: March 13, 2020 (last updated February 21, 2025)
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Attacker Value
Unknown

CVE-2017-1000486

Disclosure Date: January 03, 2018 (last updated January 23, 2025)
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution