Arturo Bernal created JSPWIKI-1204: -------------------------------------- Summary: Security Ticket: XBOW-024-109 XSS in JSPWiki Header Link Name Key: JSPWIKI-1204 URL: https://issues.apache.org/jira/browse/JSPWIKI-1204 Project: JSPWiki Issue Type: Bug Reporter: Arturo Bernal Assignee: Arturo Bernal
A vulnerability in the handling of footnote links in JSPWiki allows for XSS injection. Specifically, when an HTML or Markdown link contains malicious scripts, it is improperly rendered in the output, leading to a potential XSS attack. -- This message was sent by Atlassian Jira (v8.20.10#820010)