Description

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Remediation

References

Related Vulnerabilities

Severity

Critical

Classification

CWE-79

Tags

Vendor Advisory