CVE-2025-24853 Details
Description
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team showed that the markdown parser allowed this kind of attack too. Apache JSPWiki users should upgrade to 2.12.3 or later.
A cross-site scripting (XSS) vulnerability has been identified in Apache JSPWiki versions prior to 2.12.2. This issue arises when a user creates a header link using wiki markup syntax, allowing an attacker to execute JavaScript in the victim's browser and potentially access sensitive information about the victim. Further investigation revealed that the markdown parser is also susceptible to this type of attack.
Users of Apache JSPWiki are advised to upgrade to version 2.12.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/07/30/2 | CVE | |
| https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2025-24853 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache jspwiki | < 2.12.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Aug 4, 2025 | Initial Analysis | [email protected] |
| Jul 31, 2025 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | New CVE Received | [email protected] |