Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Poh Jia

#43004of 53,639
6.1Total CVSS
Vulnerabilities · 1
PT-2022-19198
6.1
2022-08-04
Apache · Apache Jspwiki · CVE-2022-28730
**Name of the Vulnerable Software and Affected Versions** Apache JSPWiki versions prior to 2.11.3 **Description** A carefully crafted request on "AJAXPreview.jsp" could trigger an issue that allows an attacker to execute javascript in the victim's browser and obtain sensitive information. This issue leverages a problem where the Denounce plugin dangerously renders user-supplied URLs. The patch for this problem was found to be incomplete, as it was still possible to insert malicious input via the Denounce plugin. **Recommendations** For versions prior to 2.11.3, upgrade to 2.11.3 or later. As a temporary workaround, consider disabling the Denounce plugin until a patch is available. Restrict access to the "AJAXPreview.jsp" page to minimize the risk of exploitation. Avoid using the Denounce plugin to render user-supplied URLs until the issue is resolved.