CVE-2022-28731
medium · 6.5A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
6.5
CVSS
56.9%
EPSS (exploit prob.)
99th
EPSS percentile
2022-08-04
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weaknesses
CWE-352
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | jspwiki | < 2.11.3 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-28731