oss-sec mailing list archives
[CVE-2019-0225] Apache JSPWiki Local File Inclusion (limited ROOT folder) vulnerability leads to user information disclosure
From: Juan Pablo Santos Rodríguez <juanpablo () apache org>
Date: Tue, 26 Mar 2019 22:43:09 +0100
[CVEID]:CVE-2019-0225 [PRODUCT]:Apache JSPWiki [VERSION]:Apache JSPWiki 2.9.0 to 2.11.0.M2 [PROBLEMTYPE]:Local File Inclusion (limited ROOT folder) vulnerability leads to user information disclosure [REFERENCES]:https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-0225 [DESCRIPTION]: A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki, which could be used by an attacker to obtain registered users' details.
Current thread:
- [CVE-2019-0225] Apache JSPWiki Local File Inclusion (limited ROOT folder) vulnerability leads to user information disclosure Juan Pablo Santos Rodríguez (Mar 26)