HTTP: Apache JSPWiki Upload Stored Cross-Site Scripting

This signature detects attempts to exploit a known cross-site scripting vulnerability against Apache JSPWiki. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.

Affected Products

Apache jspwiki

References

CVE: CVE-2024-27136

Short Name
HTTP:XSS:APACHE-JSPWIKI-UPLD
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Apache CVE-2024-27136 Cross-Site JSPWiki Scripting Stored Upload
Release Date
07/19/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3751
False Positive
Rarely
Vendors

Apache

Found a potential security threat?