Server side cross-site scripting In com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent
Description
Cross-site Scripting in wicket-jquery-ui In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 6.28.1, 7.9.2, 8.0.0-m8.1 |
Aliases
1. 2. 3. 4.
References
1. 2.