PT-2022-17004 · Apache · Apache Jspwiki
Paulos Yibelo
·
Published
2022-02-25
·
Updated
2022-03-05
·
CVE-2022-24948
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache JSPWiki versions prior to 2.11.2
Description
A carefully crafted user preferences submission could trigger an issue related to the user preferences screen, allowing an attacker to execute javascript in the victim's browser and potentially obtain sensitive information.
Recommendations
For versions prior to 2.11.2, upgrade to 2.11.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the user preferences screen until the upgrade is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Jspwiki