VYPR

Fitnesse Wiki

by Fitnesse

Source repositories

CVEs (3)

  • CVE-2024-23604MedMar 18, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with specially crafted multiple parameters.

  • CVE-2024-28039MedMar 18, 2024
    risk 0.38cvss 5.8epss 0.01

    Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, or cause a denial-of-service (DoS) condition.

  • CVE-2014-1216Apr 22, 2014
    risk 0.03cvss epss 0.04

    FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.