Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fxf-qj94-3f83

Опубликовано: 05 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Apache JSPWiki XSS due to crafted request on XHRHtml2Markup.jsp

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Version 2.11.3 contains a fix for the problem

Пакеты

Наименование

org.apache.jspwiki:jspwiki-main

maven
Затронутые версииВерсия исправления

<= 2.11.2

2.11.3

EPSS

Процентиль: 100%
0.85291
Высокий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 4 года назад

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

CVSS3: 6.1
nvd
почти 4 года назад

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

CVSS3: 6.1
debian
почти 4 года назад

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS ...

EPSS

Процентиль: 100%
0.85291
Высокий

6.1 Medium

CVSS3

Дефекты

CWE-79