Description
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Remediation
References
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-12404
Related Vulnerabilities
CVE-2013-4322 Vulnerability in maven package tomcat:tomcat-coyote
CVE-2018-8319 Vulnerability in npm package msrcrypto
CVE-2023-43666 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2022-43434 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner
CVE-2023-31103 Vulnerability in maven package org.apache.inlong:manager-test