Cross-Site Scripting Vulnerabilities in Apache Wicket by The Apache Software Foundation
CVE-2015-7520
6.1MEDIUM
Summary
Multiple cross-site scripting (XSS) vulnerabilities exist in the RadioGroup and CheckBoxMultipleChoice classes of Apache Wicket. These flaws can be exploited by attackers to inject arbitrary web scripts or HTML content through maliciously crafted 'value' attributes within elements, potentially compromising user sessions and data integrity. Applications utilizing affected versions of Apache Wicket are at risk and should be updated to secure their environments.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved