CVE-2019-10089: XSS
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10089?
CVE-2019-10089 is a vulnerability on Apache JSPWiki up to version 2.11.0.M4 that allows an attacker to execute JavaScript in the victim's browser and access sensitive information.
How severe is CVE-2019-10089?
CVE-2019-10089 has a severity rating of 6.1, which is considered medium.
How can an attacker exploit CVE-2019-10089?
An attacker can exploit CVE-2019-10089 by using a carefully crafted plugin link invocation to trigger an XSS vulnerability on Apache JSPWiki.
Which versions of Apache JSPWiki are affected by CVE-2019-10089?
Apache JSPWiki versions up to 2.11.0.M4, including 2.10.5, are affected by CVE-2019-10089.
Is there a fix for CVE-2019-10089?
Yes, upgrading Apache JSPWiki to version 2.11.0.M5 or later will fix the vulnerability CVE-2019-10089.