In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4840 | In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor. |
Github GHSA |
GHSA-pwpc-hqq2-hx2x | Cross-site Scripting in wicket-jquery-ui |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T02:11:55.065Z
Reserved: 2017-10-21T00:00:00
Link: CVE-2017-15719
No data.
Status : Modified
Published: 2018-03-12T13:29:00.273
Modified: 2024-11-21T03:15:04.710
Link: CVE-2017-15719
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA