Cross-site Scripting in jspwiki-war
Moderate severity
GitHub Reviewed
Published
Feb 12, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
<= 2.10.5
Patched versions
2.11.0.M1
Description
Published to the GitHub Advisory Database
Feb 12, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.
References