Cross-Site Scripting Vulnerability in Apache JSPWiki Affects Multiple Versions
CVE-2019-10077
6.1MEDIUM
What is CVE-2019-10077?
A crafted InterWiki link in Apache JSPWiki versions 2.9.0 through 2.11.0.M3 can lead to a Cross-Site Scripting (XSS) vulnerability. This issue allows remote attackers to inject arbitrary web script or HTML, potentially resulting in session hijacking. Users interacting with the malicious link may expose their session cookies or other sensitive information, thereby compromising the security and integrity of their accounts. It is advised for users to upgrade to the latest patched version to mitigate any risks associated with this vulnerability.
Affected Version(s)
Apache JSPWiki Apache JSPWiki 2.9.0 to 2.11.0.M3