CVE-2020-11976

CVE-2020-11976

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5

Source: CVE-2020-11976

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다