8.8
CVSSv3

CVE-2023-49093

Published: 04/12/2023 Updated: 11/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

htmlunit htmlunit

Vendor Advisories

Description<!---->A flaw was found in HTMLUnit Fetching external resources may be possible for XSLT processors with the Feature for Secure Processing disabled (FSP), allowing code injection and arbitrary code execution HTMLUnit is vulnerable to this type of attack by defaultA flaw was found in HTMLUnit Fetching external resources may be possibl ...