Selection:
XSS CSRF Privilege Buffer Remote Stack
CVE ID Name Status References
CVE-2021-44140

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.

Assigned (20211122)

MISC:https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2021-44140 | URL:https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2021-44140 | MISC:https://lists.apache.org/thread/5qglpjdhvobppx7j550lf1sk28f6011t | URL:https://lists.apache.org/thread/5qglpjdhvobppx7j550lf1sk28f6011t


Page created:

CVE year by year statistics.

CVE year statistics by common vulnerability domain.

Latest data from: 2024-04-25