Cross-site Scripting in wicket-jquery-ui
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
< 6.29.1
>= 7.0.0, < 7.10.2
>= 8.0.0-M1, < 8.0.0-M9.2
Patched versions
6.29.1
7.10.2
8.0.0-M9.2
Description
Published by the National Vulnerability Database
Apr 18, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Nov 3, 2022
Last updated
Feb 1, 2023
In wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
References