CVE-2011-2712: XSS
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2712?
CVE-2011-2712 is classified as a medium severity vulnerability due to its potential for Cross-site Scripting (XSS) attacks.
How do I fix CVE-2011-2712?
To mitigate CVE-2011-2712, upgrade Apache Wicket to version 1.4.18 or later where the vulnerability has been addressed.
What versions of Apache Wicket are affected by CVE-2011-2712?
CVE-2011-2712 affects Apache Wicket versions 1.4.0 through 1.4.17.
What type of attack does CVE-2011-2712 allow?
CVE-2011-2712 allows remote attackers to inject arbitrary web script or HTML through an XSS vulnerability.
Is the XSS vulnerability in CVE-2011-2712 easy to exploit?
The exploitation of the XSS vulnerability in CVE-2011-2712 may require knowledge of the application’s parameters, making it a concern for web application security.