PT-2022-19198 · Apache · Apache Jspwiki
Poh Jia
+1
·
Published
2022-08-04
·
Updated
2022-08-10
·
CVE-2022-28730
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache JSPWiki versions prior to 2.11.3
Description
A carefully crafted request on "AJAXPreview.jsp" could trigger an issue that allows an attacker to execute javascript in the victim's browser and obtain sensitive information. This issue leverages a problem where the Denounce plugin dangerously renders user-supplied URLs. The patch for this problem was found to be incomplete, as it was still possible to insert malicious input via the Denounce plugin.
Recommendations
For versions prior to 2.11.3, upgrade to 2.11.3 or later. As a temporary workaround, consider disabling the Denounce plugin until a patch is available. Restrict access to the "AJAXPreview.jsp" page to minimize the risk of exploitation. Avoid using the Denounce plugin to render user-supplied URLs until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Jspwiki