CVE-2019-10077

Severity
6.1MEDIUM
EPSS
3.1%
top 13.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateJun 6

Description

A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

Mavenorg.apache.jspwiki:jspwiki-war2.9.02.11.0.M4
Mavenorg.apache.jspwiki:jspwiki-main2.9.02.11.0.M4
NVDapache/jspwiki2.9.02.11.0+1
CVEListV5apache_software_foundation/apache_jspwikiApache JSPWiki 2.9.0 to 2.11.0.M3

🔴Vulnerability Details

3
GHSA
Cross-site Scripting in JSPWiki2019-06-06
OSV
Cross-site Scripting in JSPWiki2019-06-06
CVEList
CVE-2019-10077: A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 22019-05-20
CVE-2019-10077 (MEDIUM CVSS 6.1) | A carefully crafted InterWiki link | cvebase.io