CVE-2019-12404: XSS
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this JSPWiki vulnerability?
The vulnerability ID is CVE-2019-12404.
What is the severity of CVE-2019-12404?
The severity of CVE-2019-12404 is medium with a CVSS score of 6.1.
Which versions of Apache JSPWiki are affected by CVE-2019-12404?
Apache JSPWiki versions up to 2.11.0.M4 are affected by CVE-2019-12404.
What is the impact of CVE-2019-12404?
CVE-2019-12404 allows an attacker to trigger an XSS vulnerability, potentially executing JavaScript in the victim's browser and obtaining sensitive information.
Where can I find more information about CVE-2019-12404?
You can find more information about CVE-2019-12404 on the [Apache JSPWiki website](https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-12404).