XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-36gf-vpj2-j42w Cross site scripting in Apache JSPWiki
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache jspwiki
CPEs cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache jspwiki
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 13 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-03-20T18:03:19.410Z

Reserved: 2024-02-20T12:13:15.203Z

Link: CVE-2024-27136

cve-icon Vulnrichment

Updated: 2024-09-13T16:03:09.936Z

cve-icon NVD

Status : Modified

Published: 2024-06-24T08:15:09.297

Modified: 2025-03-20T18:15:17.993

Link: CVE-2024-27136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.