{"id":"CVE-2018-20242","details":"A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.","aliases":["GHSA-5q75-cxcq-wr26"],"modified":"2026-05-18T17:43:07.918532Z","published":"2019-02-11T21:29:00.287Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/8ee4644432c0a433c5c514a57d940cf6dcb0a0094acd97b36290f0b4%40%3Cuser.jspwiki.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/aac253cfc33c0429b528e2fcbe82d3a42d742083c528f58d192dfd16%40%3Ccommits.jspwiki.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/e42d6e93384d4a33e939989cd00ea2a06ccf1e7bb1e6bdd3bf5187c1%40%3Ccommits.jspwiki.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106804"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/jspwiki","events":[{"introduced":"0"},{"last_affected":"1b7f36e1ab997bcdc07f9f27f8ee8f692648411d"}],"database_specific":{"source":"CPE_FIELD","cpe":"cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.10.5"}]}}],"versions":["2.10.5-RC2","2.10.5","2.10.5-RC1","2.10.4-RC3","2.10.4","2.10.4-RC2","2.10.4-RC1","2.10.3-RC2","2.10.3","2.10.3-RC1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-20242.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}