-
CVSS Score
-The vulnerability description explicitly identifies XHRHtml2Markup.jsp as the entry point for crafted XSS payloads. XSS vulnerabilities typically occur when user input is directly reflected in responses without proper encoding. Given that the patch was applied in version 2.11.3 and the CWE-79 classification, the most likely root cause is improper neutralization of user-controlled input within this JSP file during response generation. The confidence is high because the advisory directly attributes the vulnerability to this component.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.jspwiki:jspwiki-main | maven | <= 2.11.2 | 2.11.3 |
A Semantic Attack on Google Gemini - Read the Latest Research