This page (revision-3) was last changed on 10-Sep-2019 16:44 by Juan Pablo 

This page was created on 19-May-2019 00:11 by Juan Pablo

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Version Date Modified Size Author Changes ... Change note
3 10-Sep-2019 16:44 735 bytes Juan Pablo to previous
2 19-May-2019 15:55 722 bytes Juan Pablo to previous | to last CVE-2019-10078
1 19-May-2019 00:11 724 bytes Juan Pablo to last
Incoming links Outgoing links

Difference between version and

At line 2 changed 2 lines
[{ALLOW view Admin}]
!! [[CVE-2019-10078] Apache JSPWiki Cross-site scripting vulnerability on Apache JSPWiki
[{ALLOW view All}]
!! [[CVE-2019-10078] Apache JSPWiki Cross-site scripting vulnerability on {{ReferredPagesPlugin}}
At line 15 changed one line
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, which could lead to session hijacking. Initial reporting indicated {{ReferredPagesPlugin}}, but further analysis showed that multiple plugins were vulnerable.