CVE-2022-27166: XSS vulnerability on XHRHtml2Markup.jsp in JSPWiki 2.11.2
Published Aug 4, 2022
·Updated
A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Affected Software
1 affected component
Apache JSPWiki<2.11.3
Event History
Aug 4, 2022
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-27166?
The severity of CVE-2022-27166 is medium with a CVSS score of 6.1.
2
How does CVE-2022-27166 affect Apache JSPWiki?
CVE-2022-27166 affects Apache JSPWiki up to and including version 2.11.2.
3
What type of vulnerability is CVE-2022-27166?
CVE-2022-27166 is an XSS (Cross-Site Scripting) vulnerability.
4
What is the potential impact of CVE-2022-27166?
CVE-2022-27166 could allow an attacker to execute javascript in the victim's browser and gain access to sensitive information.
5
Is there a fix available for CVE-2022-27166?
Upgrading to version 2.11.3 or above of Apache JSPWiki fixes the CVE-2022-27166 vulnerability.