Description
In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
Remediation
References
https://markmail.org/message/6bxjyaolehhq7jrl
Related Vulnerabilities
CVE-2019-16562 Vulnerability in maven package org.jenkins-ci.plugins:buildgraph-view
CVE-2019-1010091 Vulnerability in maven package org.webjars.bower:tinymce
CVE-2017-14063 Vulnerability in maven package org.asynchttpclient:async-http-client
CVE-2017-7664 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2022-36901 Vulnerability in maven package org.jenkins-ci.plugins:http_request