CVE-2023-26119
HtmlUnit Code Injection vulnerability
Description
Versions of the package net.sourceforge.htmlunit:htmlunit
from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
Base CVSS
9.8
EPSS Score
3.1%
Introduced Version
1.14
Fix Available
3.0.0
Available Patches
Package
CVEs Fixed
Lines of Code Changed