XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.
History

Thu, 17 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache jspwiki
CPEs cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache jspwiki
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 13 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-06-24T07:44:30.732Z

Updated: 2024-09-13T16:03:09.936Z

Reserved: 2024-02-20T12:13:15.203Z

Link: CVE-2024-27136

cve-icon Vulnrichment

Updated: 2024-09-13T16:03:09.936Z

cve-icon NVD

Status : Modified

Published: 2024-06-24T08:15:09.297

Modified: 2024-11-21T09:03:55.410

Link: CVE-2024-27136

cve-icon Redhat

No data.