CVE-2024-27136: Apache JSPWiki: Cross-site scripting vulnerability on upload page
Published Jun 23, 2024
·Updated
XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.
Affected Software
2 affected componentsFixes available
Apache JSPWiki<2.12.2
maven/org.apache.jspwiki:jspwiki-main<2.12.2
2.12.2
Event History
Jun 24, 2024
CVE Published
via MITRE·07:44 AM
Data Sourced
via MITRE·07:44 AM
DescriptionWeakness
Advisory Published
via GitHub·09:30 AM
Data Sourced
via GitHub·09:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27136?
CVE-2024-27136 has a severity rating that indicates a critical risk due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-27136?
To fix CVE-2024-27136, upgrade Apache JSPWiki to version 2.12.2 or later.
3
Which versions of Apache JSPWiki are affected by CVE-2024-27136?
Apache JSPWiki versions 2.12.1 and prior are affected by CVE-2024-27136.
4
What type of vulnerability is CVE-2024-27136?
CVE-2024-27136 is a cross-site scripting (XSS) vulnerability that allows attackers to execute JavaScript in victims' browsers.
5
What can attackers achieve through CVE-2024-27136?
Attackers can leverage CVE-2024-27136 to execute malicious scripts and steal sensitive information from victims.