PT-2022-19200 · Apache · Apache Jspwiki

Wang Ran

·

Published

2022-08-04

·

Updated

2022-08-10

·

CVE-2022-28732

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache JSPWiki versions prior to 2.11.3
Description A carefully crafted request could trigger a vulnerability on Apache JSPWiki, allowing an attacker to execute javascript in the victim's browser and obtain sensitive information. The issue can be triggered through specific requests on certain plugins or pages, such as WeblogPlugin or XHRHtml2Markup.jsp.
Recommendations For versions prior to 2.11.3, upgrade to 2.11.3 or later to resolve the issue. As a temporary workaround, consider restricting access to vulnerable plugins or pages, such as WeblogPlugin or XHRHtml2Markup.jsp, until the upgrade is applied.

Fix

XSS

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28732
GHSA-2FXF-QJ94-3F83
GHSA-9X9J-VRHJ-V364
GHSA-GGJQ-8C4C-68R5
GHSA-HPH8-29XW-QFXX

Affected Products

Apache Jspwiki