以下是对该漏洞描述的中文翻译: 漏洞描述: 在使用 中,当 使用非空的 构造时,会将来自该渲染器的显示值直接写入标签的标记(markup),而未应用 Wicket 默认对组件模型值进行的 HTML 转义。 这意味着,任何能够影响该标签所渲染的选项或模型数据的攻击者,可以注入 HTML 或脚本,并在查看页面的任何用户的浏览器中执行。需要注意的是,同一数值在该组件的下拉编辑器渲染为选项时是正确转义的,因此只有标签的渲染部分受到影响。 、 和 在组件模型为空时,会将受保护的 方法返回的值以相同方式写入标签的标记,而在模型
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Wicket | 8.0.0 ~ 8.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58301 | 5.9 MEDIUM | Apache Shiro: Server-side POST request may be steered to an alternate host |
| CVE-2026-76983 | 5.1 MEDIUM | Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel |
| CVE-2026-76984 | 5.1 MEDIUM | Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute |
| CVE-2026-76982 | 5.1 MEDIUM | Apache Wicket: XSS in Button via its model object |
| CVE-2026-71378 | Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationReq | |
| CVE-2026-71257 | Apache Wicket: Configured file upload limits are not enforced when the multipart request h | |
| CVE-2026-70449 | Apache Wicket: Path traversal in resource style/variation/locale |
No comments yet