CVE-2019-10090: XSS
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10090?
CVE-2019-10090 is a vulnerability on Apache JSPWiki that could allow an attacker to execute JavaScript in the victim's browser and access sensitive information.
How does CVE-2019-10090 work?
CVE-2019-10090 can be triggered by a carefully crafted plugin link invocation, which can lead to an XSS vulnerability in Apache JSPWiki's plain editor.
What is the severity of CVE-2019-10090?
CVE-2019-10090 has a severity level of 6.1 (Medium) according to the Common Vulnerability Scoring System (CVSS).
How can I fix CVE-2019-10090?
To fix CVE-2019-10090, you should upgrade Apache JSPWiki to version 2.11.0.M4 or later.
Where can I find more information about CVE-2019-10090?
You can find more information about CVE-2019-10090 on the Apache JSPWiki website at the following link: https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-10090