CVE-2022-24948: Apache JSPWiki Cross-site scripting vulnerability on User Preferences screen
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.2 or later.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2022-24948.
What is the severity of CVE-2022-24948?
The severity of CVE-2022-24948 is medium, with a CVSS score of 6.1.
How does this vulnerability impact Apache JSPWiki?
This vulnerability could allow an attacker to execute JavaScript in the victim's browser and potentially gain access to sensitive information about the victim.
How can I protect my Apache JSPWiki installation from this vulnerability?
To protect your Apache JSPWiki installation, make sure to upgrade to a version above 2.11.2, as this vulnerability has been patched in later versions.
Where can I find more information about CVE-2022-24948?
You can find more information about CVE-2022-24948 on the Openwall mailing list and the Apache JSPWiki mailing list.