Closed
Description
CoreNLP/src/edu/stanford/nlp/ie/ner/webapp/NERServlet.java
Lines 152 to 159 in d147ba5
We found 'classifier' may be contaminated on line 152 of NERServlet.java.java.Including unvalidated data in an HTTP response header can enable cache-poisoning, cross-site scripting, cross-user defacement, page hijacking, cookie manipulation or open redirect..It will affect on line 157 of NERServlet.java.Lines 158 and 159 have similar problems.