Cross-Site Scripting Vulnerabilities in Apache Wicket by The Apache Software Foundation
CVE-2015-7520

6.1MEDIUM

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
12 April 2016

Summary

Multiple cross-site scripting (XSS) vulnerabilities exist in the RadioGroup and CheckBoxMultipleChoice classes of Apache Wicket. These flaws can be exploited by attackers to inject arbitrary web scripts or HTML content through maliciously crafted 'value' attributes within elements, potentially compromising user sessions and data integrity. Applications utilizing affected versions of Apache Wicket are at risk and should be updated to secure their environments.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.