Description
In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
Remediation
References
https://markmail.org/message/6bxjyaolehhq7jrl
Related Vulnerabilities
CVE-2019-10374 Vulnerability in maven package org.jenkins-ci.plugins:pegdown-formatter
CVE-2019-16772 Vulnerability in maven package org.webjars.npm:serialize-javascript
CVE-2016-3092 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2019-13000 Vulnerability in maven package fr.acinq.eclair:eclair-core_2.11
CVE-2020-6831 Vulnerability in maven package org.webjars.npm:electron