CVE-2019-10090

MEDIUM

Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via Plugin Link Invocation

Title source: llm
STIX 2.1

Description

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0437
EPSS Percentile 89.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
apache/jspwiki 2.11.0 m1 (12 CPE variants)
apache/jspwiki < 2.10.5
org.apache.jspwiki/jspwiki-war 2.9.0 - 2.11.0.M5Maven
Published Sep 23, 2019
Tracked Since Feb 18, 2026