Описание
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.10.5 (включая)
Одно из
cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m1:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m1-rc1:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m1-rc2:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m1-rc3:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m2:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m2-rc1:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m3:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m3-rc1:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m3-rc2:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m4:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m4-rc1:*:*:*:*:*:*
cpe:2.3:a:apache:jspwiki:2.11.0:m4-rc2:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04374
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
debian
больше 6 лет назад
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin ...
EPSS
Процентиль: 89%
0.04374
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79