https://seclists.org/oss-sec/2024/q2/298: CVE-2024-27136: Apache JSPWiki: Cross-site scripting vulnerability on upload page
Published Jun 23, 2024
·Updated
Affected Software
1 affected component
Apache JSPWiki<=2.12.1
Frequently Asked Questions
1
What is the severity of CVE-2024-27136?
The severity of CVE-2024-27136 is classified as moderate.
2
Which versions of Apache JSPWiki are affected by CVE-2024-27136?
Apache JSPWiki versions through 2.12.1 are affected by CVE-2024-27136.
3
What type of vulnerability is CVE-2024-27136?
CVE-2024-27136 is a cross-site scripting (XSS) vulnerability on the upload page.
4
How do I fix CVE-2024-27136?
To fix CVE-2024-27136, Apache JSPWiki users should upgrade to version 2.12.2 or later.
5
What could an attacker achieve by exploiting CVE-2024-27136?
An attacker exploiting CVE-2024-27136 could execute JavaScript in the victim's browser to obtain sensitive information.