A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.jspwiki:jspwiki-war(Maven) | 2.9.0 | 2.11.0.M4 | N/A |
| org.apache.jspwiki:jspwiki-main(Maven) | 2.9.0 | 2.11.0.M4 | N/A |
CVSS Metrics