CVE-2019-10076
20.05.2019, 21:29
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
Vendor | Product | Version |
---|---|---|
apache | jspwiki | 2.9.0 ≤ 𝑥 ≤ 2.11.0 |
apache | jspwiki | 2.11.0:m1 |
apache | jspwiki | 2.11.0:m1-rc1 |
apache | jspwiki | 2.11.0:m1-rc2 |
apache | jspwiki | 2.11.0:m1.rc3 |
apache | jspwiki | 2.11.0:m2 |
apache | jspwiki | 2.11.0:m2-rc1 |
𝑥
= Vulnerable software versions
References