Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fxf-qj94-3f83

Опубликовано: 05 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Apache JSPWiki XSS due to crafted request on XHRHtml2Markup.jsp

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Version 2.11.3 contains a fix for the problem

Пакеты

Наименование

org.apache.jspwiki:jspwiki-main

maven
Затронутые версииВерсия исправления

<= 2.11.2

2.11.3

EPSS

Процентиль: 92%
0.08595
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

CVSS3: 6.1
nvd
больше 3 лет назад

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

CVSS3: 6.1
debian
больше 3 лет назад

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS ...

EPSS

Процентиль: 92%
0.08595
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79