Cross-Site Scripting in JSPWiki
Moderate severity
GitHub Reviewed
Published
Jun 6, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
May 29, 2019
Published to the GitHub Advisory Database
Jun 6, 2019
Last updated
Jan 9, 2023
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
References