CVE-2022-24947

HIGH

Apache JSPWiki < 2.11.2 - Cross-Site Request Forgery in User Preferences Form

Title source: llm
STIX 2.1

Description

Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.

References (2)

Core 2
Core References
Mailing List, Mitigation, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread/txrgykjkpt80t57kzpbjo8kfrv8ss02c
Mailing List, Mitigation, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/02/25/1

Scores

CVSS v3 8.8
EPSS 0.0185
EPSS Percentile 83.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (2)
apache/jspwiki < 2.11.2
org.apache.jspwiki/jspwiki-main 0 - 2.11.2Maven
Published Feb 25, 2022
Tracked Since Feb 18, 2026