First published: Thu Aug 04 2022(Updated: )
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or later.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache JSPWiki | <2.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-28732.
The severity of CVE-2022-28732 is medium with a CVSS score of 6.1.
The affected software for CVE-2022-28732 is Apache JSPWiki versions up to 2.11.3.
To fix the CVE-2022-28732 vulnerability, Apache JSPWiki users should upgrade to version 2.11.3 or later.
You can find more information about CVE-2022-28732 on the Apache JSPWiki website.