A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.
| Software | From | Fixed in |
|---|---|---|
| apache / jspwiki | - | 2.10.5.x |
org.apache.jspwiki / jspwiki-war
|
- | 2.11.0.M1 |