CVE-2019-10076
MEDIUMApache JSPWiki 2.9.0-2.11.0.M3 - Stored Cross-Site Scripting via Malicious Attachment
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-10076. PoCs published by shoucheng3.
AI-analyzed exploit summary This repository contains the Apache JSPWiki source code and integration tests, but no functional exploit code for CVE-2019-10076. The README provides installation and configuration details for JSPWiki, while the Java files are integration tests for UI functionality.
Description
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
Exploits (1)
This repository contains the Apache JSPWiki source code and integration tests, but no functional exploit code for CVE-2019-10076. The README provides installation and configuration details for JSPWiki, while the Java files are integration tests for UI functionality.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N