Description
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/05/25/1
https://lists.apache.org/thread/1m0mkq2nttx8tn94m11mytn4f0tv1504
Related Vulnerabilities
CVE-2022-43426 Vulnerability in maven package io.jenkins.plugins:s3explorer
CVE-2019-10287 Vulnerability in maven package org.jenkins-ci.plugins:youtrack-plugin
CVE-2019-16572 Vulnerability in maven package org.jenkins-ci.plugins:weibo
CVE-2021-42767 Vulnerability in maven package org.neo4j.procedure:apoc
CVE-2020-5258 Vulnerability in maven package org.webjars.bower:dojo