CVE-2024-27136

CVE-2024-27136: Apache JSPWiki: Cross-site scripting vulnerability on upload page

Vendor Apache Software Foundation
Product Apache JSPWiki
Weakness CWE-79 · XSS
Published June 24, 2024
Last update March 20, 2025

CVSS base score

What the vulnerability does

Description

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.

Key dates

Disclosure timeline

June 24, 2024 CVE published
March 20, 2025 Record updated