Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processing
Vulnerability Description
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team showed that the markdown parser allowed this kind of attack too. Apache JSPWiki users should upgrade to 2.12.3 or later.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24853
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- The issue was discovered by XBOW (https://github.com/xbow-security, https://xbow.com)
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →