CVE-2021-44140
24.11.2021, 12:15
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.Enginsight
Vendor | Product | Version |
---|---|---|
apache | jspwiki | 𝑥 < 2.11.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration