vendor:
JSPWiki
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: JSPWiki
Affected Version From: 2.1.0120
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2004-2689
CPE: a:jspwiki:jspwiki:2.1.120
Platforms Tested: Unknown
Unknown
Cross-Site Scripting Vulnerability in JSPWiki
JSPWiki is susceptible to a cross-site scripting vulnerability. This issue allows a remote attacker to create a malicious URI link that includes hostile HTML and script code. If the link is followed, the hostile code may be rendered in the web browser of the victim user, potentially leading to theft of authentication credentials or other attacks.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of JSPWiki.