oss-sec mailing list archives

CVE-2022-28732: Apache JSPWiki Cross-site scripting vulnerability on WeblogPlugin


From: Juan Pablo Santos Rodríguez <juanpablo () apache org>
Date: Wed, 03 Aug 2022 20:46:18 +0000

Severity: moderate

Description:

A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the 
attacker to execute javascript in the victim's browser and get some sensitive information about the victim. 

Mitigation:

Apache JSPWiki users should upgrade to 2.11.3 or later. 

Credit:

This issue was discovered by Wang Ran, from JDArmy, @jd.com 

References:

https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732


Current thread: