CVE-2019-10089
MEDIUM 6.1EPSS 2.9%
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 2.90% chance of exploitation in the next 30 days, 86th percentile
- Published
- 2019-09-23
- Updated
- 2024-08-04
Proof-of-concept exploits (1)
- shoucheng3/apache__jspwiki_CVE-2019-10089_2-11-0-M40★ · 2025-08-18