A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
| Software | From | Fixed in |
|---|---|---|
| apache / jspwiki | 2.9.0 | 2.11.0.x |
| apache / jspwiki | 2.11.0-m1-rc2 | 2.11.0-m1-rc2.x |
| apache / jspwiki | 2.11.0-m1.rc3 | 2.11.0-m1.rc3.x |
| apache / jspwiki | 2.11.0-m1 | 2.11.0-m1.x |
| apache / jspwiki | 2.11.0-m2-rc1 | 2.11.0-m2-rc1.x |
| apache / jspwiki | 2.11.0-m2 | 2.11.0-m2.x |
| apache / jspwiki | 2.11.0-m1-rc1 | 2.11.0-m1-rc1.x |
org.apache.jspwiki / jspwiki-war
|
2.9.0 | 2.11.0.M4 |
org.apache.jspwiki / jspwiki-main
|
2.9.0 | 2.11.0.M4 |