{"id":"CVE-2019-10078","details":"A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.","aliases":["GHSA-hp5r-mhgp-56c9"],"modified":"2026-09-11T14:11:39.793522Z","published":"2019-05-20T21:29:00.877Z","references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2019/05/19/6"},{"type":"WEB","url":"http://www.securityfocus.com/bid/108437"},{"type":"WEB","url":"https://lists.apache.org/thread.html/24f324ef11e43ba89ec9aac3725a5ecd4289835639c476299e7660d9%40%3Cdev.jspwiki.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/959811b776e1a332a1a4295405b683fd64190d079a7c3028f1c314d7%40%3Cdev.jspwiki.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/aac253cfc33c0429b528e2fcbe82d3a42d742083c528f58d192dfd16%40%3Ccommits.jspwiki.apache.org%3E"},{"type":"ADVISORY","url":"https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-10078"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/jspwiki","events":[{"introduced":"6144474e52dcfa101c181a5ee0ebf9a7c9c53d17"},{"last_affected":"b9c3d919beee3a73ffd87cde5021327d3a6544a5"},{"introduced":"c2b84e0c9bae48dee127026a4d8a2c68123656dd"},{"last_affected":"d48bcef107a14dd07ecd830ab817b8df796082a4"}],"database_specific":{"cpe":["cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m1:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m1-rc1:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m1-rc2:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m1.rc3:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m2:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m2-rc1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.9.0"},{"last_affected":"2.11.0"},{"introduced":"2.11.0-m1"},{"last_affected":"2.11.0-m1"},{"introduced":"2.11.0-m1\\-rc1"},{"last_affected":"2.11.0-m1\\-rc1"},{"introduced":"2.11.0-m1\\-rc2"},{"last_affected":"2.11.0-m1\\-rc2"},{"introduced":"2.11.0-m1\\.rc3"},{"last_affected":"2.11.0-m1\\.rc3"},{"introduced":"2.11.0-m2"},{"last_affected":"2.11.0-m2"},{"introduced":"2.11.0-m2\\-rc1"},{"last_affected":"2.11.0-m2\\-rc1"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.11.0-m1","2.11.0-m1\\-rc1","2.11.0-m1\\-rc2","2.11.0-m1\\.rc3","2.11.0-m2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10078.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}