CVE-2016-0711

Severity
6.1MEDIUM
EPSS
2.6%
top 14.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 11
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Apache Jetspeed vulnerable to Cross-site Scripting2022-05-17
GHSA
Apache Jetspeed vulnerable to Cross-site Scripting2022-05-17
CVEList
CVE-2016-0711: Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 22016-04-11

💬Community

4
Bugzilla
CVE-2016-0791 jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)2016-02-25
Bugzilla
CVE-2016-0788 jenkins: Remote code execution vulnerability in remoting module (SECURITY-232)2016-02-25
Bugzilla
CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)2016-02-25
Bugzilla
CVE-2016-0790 jenkins: Non-constant time comparison of API token (SECURITY-241)2016-02-25
CVE-2016-0711 (MEDIUM CVSS 6.1) | Multiple cross-site scripting (XSS) | cvebase.io