CVE-2018-20242: XSS
Published Feb 11, 2019
·Updated
A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.
Affected Software
1 affected component
Apache JSPWiki<=2.10.5
Event History
Feb 11, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-20242.
2
What is the severity of CVE-2018-20242?
The severity of CVE-2018-20242 is medium.
3
What is the affected software for CVE-2018-20242?
The affected software for CVE-2018-20242 is Apache JSPWiki versions up to 2.10.5.
4
What is the risk of CVE-2018-20242?
CVE-2018-20242 can lead to session hijacking.
5
How can I fix CVE-2018-20242?
To fix CVE-2018-20242, update Apache JSPWiki to version 2.10.6 or later.