Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| net.sourceforge.htmlunit:htmlunit(Maven) | 0 | 3.0.0 | N/A |
CVSS Metrics