Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hph8-29xw-qfxx

Опубликовано: 05 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Apache JSPWiki XSS due to crafted request in WeblogPlugin

A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or later.

Пакеты

Наименование

org.apache.jspwiki:jspwiki-main

maven
Затронутые версииВерсия исправления

< 2.11.3

2.11.3

EPSS

Процентиль: 92%
0.08595
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or later.

CVSS3: 6.1
nvd
больше 3 лет назад

A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or later.

CVSS3: 6.1
debian
больше 3 лет назад

A carefully crafted request on WeblogPlugin could trigger an XSS vulne ...

EPSS

Процентиль: 92%
0.08595
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79