← Back to browse · API

CVE-2024-27136

Severity
MEDIUM
CVSS
6.1
EPSS
0.5943
Risk score
45.2
CISA KEV
No
PoC
No
Published
2024-06-24
Modified
2025-03-20
First seen
2026-08-07
Aliases
EUVD-2024-1896, GHSA-36GF-VPJ2-J42W
Products
Apache Software Foundation:Apache JSPWiki 0 ≤2.12.1
Sources
euvd EUVD-2024-1896

Description

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.

References