Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-0224

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.03
EPSS Ranking 86.0%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
References
Products affected by CVE-2019-0224
  • Apache » Jspwiki » Version: 2.10.0
    cpe:2.3:a:apache:jspwiki:2.10.0
  • Apache » Jspwiki » Version: 2.10.1
    cpe:2.3:a:apache:jspwiki:2.10.1
  • Apache » Jspwiki » Version: 2.10.2
    cpe:2.3:a:apache:jspwiki:2.10.2
  • Apache » Jspwiki » Version: 2.10.3
    cpe:2.3:a:apache:jspwiki:2.10.3
  • Apache » Jspwiki » Version: 2.10.4
    cpe:2.3:a:apache:jspwiki:2.10.4
  • Apache » Jspwiki » Version: 2.10.5
    cpe:2.3:a:apache:jspwiki:2.10.5
  • Apache » Jspwiki » Version: 2.11.0
    cpe:2.3:a:apache:jspwiki:2.11.0
  • Apache » Jspwiki » Version: 2.9.0
    cpe:2.3:a:apache:jspwiki:2.9.0
  • Apache » Jspwiki » Version: 2.9.1
    cpe:2.3:a:apache:jspwiki:2.9.1


Contact Us

Shodan ® - All rights reserved