First published: Fri Feb 25 2022(Updated: )
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache JSPWiki | <2.11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-24947.
The title of the vulnerability is 'Apache JSPWiki user preferences form is vulnerable to CSRF attacks which can lead to account takeover.'
The severity of CVE-2022-24947 is high (8.8).
CVE-2022-24947 affects Apache JSPWiki version 2.11.2 and earlier.
Apache JSPWiki users should upgrade to version 2.11.2 or later to protect themselves from CVE-2022-24947.