← All CVEs

CVE-2019-0225

high · 7.5

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.

7.5
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2019-03-28
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
apachejspwiki>= 2.9.0, < 2.11.0
apachejspwiki2.11.0
apachejspwiki2.11.0
apachejspwiki2.11.0
apachejspwiki2.11.0
apachejspwiki2.11.0
apachejspwiki2.11.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-0225