CVE-2022-28731: Apache JSPWiki CSRF in UserPreferences.jsp
Published Aug 4, 2022
·Updated
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
Affected Software
1 affected component
Apache JSPWiki<2.11.3
Event History
Aug 4, 2022
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-28731.
2
What is the severity of CVE-2022-28731?
The severity of CVE-2022-28731 is medium with a severity value of 6.5.
3
How does CVE-2022-28731 affect Apache JSPWiki?
CVE-2022-28731 affects Apache JSPWiki versions up to and including 2.11.3.
4
What is the impact of CVE-2022-28731?
The impact of CVE-2022-28731 is that it allows an attacker to modify the email associated with the targeted account and initiate a password reset request.
5
Is there a fix available for CVE-2022-28731?
Yes, a fix is available for CVE-2022-28731. It is recommended to upgrade Apache JSPWiki to version 2.11.4 or later.