A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.
2019-03-28T22:29:00.683
2024-11-21T04:16:32.130
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:C/I:N/A:N
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | jspwiki | < 2.11.0 | Yes |
Application | apache | jspwiki | 2.11.0 | Yes |
Application | apache | jspwiki | 2.11.0 | Yes |
Application | apache | jspwiki | 2.11.0 | Yes |
Application | apache | jspwiki | 2.11.0 | Yes |
Application | apache | jspwiki | 2.11.0 | Yes |
Application | apache | jspwiki | 2.11.0 | Yes |