Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-0224

Опубликовано: 28 мар. 2019
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*
Версия от 2.9.0 (включая) до 2.10.5 (включая)
cpe:2.3:a:apache:jspwiki:2.11.0:milestone1:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:milestone1-rc1:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:milestone1-rc2:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:milestone1-rc3:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:milestone2:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:milestone2-rc1:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.025
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 7 лет назад

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.

CVSS3: 6.1
debian
почти 7 лет назад

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could ex ...

CVSS3: 6.1
github
почти 7 лет назад

Moderate severity vulnerability that affects org.apache.jspwiki:jspwiki-main

EPSS

Процентиль: 85%
0.025
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79