CVE-2018-1325

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1325
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1325.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1325
Aliases
Published
2018-04-18T19:29:00Z
Modified
2024-09-03T02:05:02.915668Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.

References

Affected packages

Git / github.com/sebfz1/wicket-jquery-ui

Affected versions

wicket-jquery-ui-7.*

wicket-jquery-ui-7.0.1
wicket-jquery-ui-7.0.2
wicket-jquery-ui-7.1.0
wicket-jquery-ui-7.10.0
wicket-jquery-ui-7.10.1
wicket-jquery-ui-7.2.0
wicket-jquery-ui-7.2.1
wicket-jquery-ui-7.3.0
wicket-jquery-ui-7.3.1
wicket-jquery-ui-7.4.0
wicket-jquery-ui-7.5.0
wicket-jquery-ui-7.6.0
wicket-jquery-ui-7.7.0
wicket-jquery-ui-7.8.0
wicket-jquery-ui-7.9.0
wicket-jquery-ui-7.9.2

wicket-jquery-ui-8.*

wicket-jquery-ui-8.0.0-M1
wicket-jquery-ui-8.0.0-M1.1
wicket-jquery-ui-8.0.0-M2
wicket-jquery-ui-8.0.0-M3

wicket-jquery-ui-parent-7.*

wicket-jquery-ui-parent-7.9.1