First published: Sun Jun 23 2024(Updated: )
XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.jspwiki:jspwiki-main | <2.12.2 | 2.12.2 |
Apache JSPWiki | <2.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27136 has a severity rating that indicates a critical risk due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2024-27136, upgrade Apache JSPWiki to version 2.12.2 or later.
Apache JSPWiki versions 2.12.1 and prior are affected by CVE-2024-27136.
CVE-2024-27136 is a cross-site scripting (XSS) vulnerability that allows attackers to execute JavaScript in victims' browsers.
Attackers can leverage CVE-2024-27136 to execute malicious scripts and steal sensitive information from victims.