Cross-Site Scripting Vulnerability in Apache Wicket by Apache
CVE-2012-0047

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
23 March 2012

Summary

A cross-site scripting vulnerability exists in Apache Wicket 1.4.x prior to version 1.4.20. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML into the application through the 'wicket:pageMapName' request parameter. As a result, if exploited, this vulnerability can lead to unauthorized access and manipulation of user sessions, posing significant risks to users and applications utilizing affected versions of Apache Wicket.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.