CVE-2024-27136
medium · 6.1XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.
6.1
CVSS
60.8%
EPSS (exploit prob.)
99th
EPSS percentile
2024-06-24
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | jspwiki | < 2.12.2 |
Check a specific version with /api/v1/cve/match.
References
- https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2024-27136
- https://lists.apache.org/thread/gfms8gbncqqkj52p861b8fnsypwsl1d5
- http://www.openwall.com/lists/oss-security/2024/06/23/3
- https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2024-27136
- https://lists.apache.org/thread/gfms8gbncqqkj52p861b8fnsypwsl1d5
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-27136