Cross-site Scripting (XSS) Affecting org.apache.jspwiki:jspwiki-war package, versions [,2.11.0.M5)
Threat Intelligence
EPSS
0.19% (57th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHEJSPWIKI-468991
- published 23 Sep 2019
- disclosed 28 May 2019
- credit Unknown
Introduced: 28 May 2019
CVE-2019-12404 Open this link in a new tabHow to fix?
Upgrade org.apache.jspwiki:jspwiki-war
to version 2.11.0.M5 or higher.
Overview
org.apache.jspwiki:jspwiki-war is an open source WikiWiki engine, feature-rich and built around standard JEE components (Java, servlets, JSP).
Affected versions of this package are vulnerable to Cross-site Scripting (XSS).
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp
, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Details
References
CVSS Scores
version 3.1