Cross-Site Scripting Vulnerability in Apache JSPWiki
CVE-2019-10089
6.1MEDIUM
Summary
Apache JSPWiki versions up to 2.11.0.M4 are susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper handling of carefully crafted plugin link invocations. This vulnerability is associated with the WYSIWYG editor component, allowing an attacker to inject malicious JavaScript into a victim's browser. Such an attack could lead to unauthorized access to sensitive information from the victim, posing a significant threat to web application security.
Affected Version(s)
Apache JSPWiki Apache JSPWiki up to 2.11.0.M4
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved