{"id":"GHSA-pwpc-hqq2-hx2x","summary":"Cross-site Scripting in wicket-jquery-ui","details":"In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.","aliases":["CVE-2017-15719"],"modified":"2023-11-01T04:47:44.913349Z","published":"2022-05-14T00:58:28Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-03T19:08:08Z","nvd_published_at":"2018-03-12T13:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15719"},{"type":"WEB","url":"https://github.com/sebfz1/wicket-jquery-ui/wiki#cve-2017-15719---xss-in-wysiwyg-editor"},{"type":"WEB","url":"http://openmeetings.apache.org/security.html#_toc_cve-2017-15719_-_wicket_jquery_ui_xss_in_wysiwyg_e"}],"affected":[{"package":{"name":"com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent","ecosystem":"Maven","purl":"pkg:maven/com.googlecode.wicket-jquery-ui/wicket-jquery-ui-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.28.1"}]}],"versions":["1.5.10","1.5.11","6.10.0","6.11.0","6.12.0","6.13.0","6.13.1","6.14.0","6.15.0","6.16.0","6.17.0","6.18.0","6.18.1","6.19.0","6.19.1","6.19.2","6.19.3","6.20.0","6.20.1","6.20.2","6.20.3","6.21.0","6.21.1","6.21.2","6.22.0","6.22.1","6.22.2","6.23.0","6.24.0","6.25.0","6.25.1","6.26.0","6.27.0","6.28.0","6.7.0","6.8.0","6.8.1","6.9.0","6.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pwpc-hqq2-hx2x/GHSA-pwpc-hqq2-hx2x.json"}},{"package":{"name":"com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent","ecosystem":"Maven","purl":"pkg:maven/com.googlecode.wicket-jquery-ui/wicket-jquery-ui-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.9.2"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.1.0","7.2.0","7.2.1","7.3.0","7.3.1","7.4.0","7.5.0","7.6.0","7.7.0","7.8.0","7.9.0","7.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pwpc-hqq2-hx2x/GHSA-pwpc-hqq2-hx2x.json"}},{"package":{"name":"com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent","ecosystem":"Maven","purl":"pkg:maven/com.googlecode.wicket-jquery-ui/wicket-jquery-ui-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0-M1"},{"fixed":"8.0.0-M8.1"}]}],"versions":["8.0.0-M1","8.0.0-M1.1","8.0.0-M2","8.0.0-M3","8.0.0-M4","8.0.0-M4.1","8.0.0-M5","8.0.0-M6","8.0.0-M7","8.0.0-M8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pwpc-hqq2-hx2x/GHSA-pwpc-hqq2-hx2x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}