Apache JSPWiki Cross-site Scripting due to carefully crafted plugin link invocation
Moderate severity
GitHub Reviewed
Published
Dec 2, 2021
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Nov 24, 2021
Reviewed
Nov 25, 2021
Published to the GitHub Advisory Database
Dec 2, 2021
Last updated
Jan 30, 2023
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.0 or later.
References