CVE-2024-27136
Apache
CVE-2024-27136: A cross-site scripting (XSS) vulnerability exists in the Upload page of Apache JSPWiki versions 2.12.1 and earlier. This flaw enables an attacker to inject malicious JavaScript code into a victim's browser, potentially leading to the theft of sensitive information. Although the CVSS score is 6.1, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate risk compared to critical vulnerabilities. However, the presence of the "In The Wild" tag highlights active exploitation. Apache JSPWiki users are strongly advised to upgrade to version 2.12.2 or later to mitigate this security risk. Failure to patch could expose users to account hijacking or data breaches. The attack involves injecting script through upload functionality.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.