CVE-2019-10077: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
References
Detect and mitigate CVE-2019-10077 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →