Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hp5r-mhgp-56c9

Опубликовано: 06 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site Scriptin in JSPWiki

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.

Пакеты

Наименование

org.apache.jspwiki:jspwiki-war

maven
Затронутые версииВерсия исправления

>= 2.9.0, <= 2.11.0.M3

2.11.0.M4

Наименование

org.apache.jspwiki:jspwiki-main

maven
Затронутые версииВерсия исправления

>= 2.9.0, <= 2.11.0.M3

2.11.0.M4

EPSS

Процентиль: 87%
0.03225
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.

CVSS3: 6.1
nvd
больше 6 лет назад

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.

CVSS3: 6.1
debian
больше 6 лет назад

A carefully crafted plugin link invocation could trigger an XSS vulner ...

EPSS

Процентиль: 87%
0.03225
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79