CVE-2022-24947

Severity
8.8HIGH
EPSS
1.8%
top 17.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateFeb 26

Description

Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDapache/jspwiki< 2.11.2
CVEListV5apache_software_foundation/apache_jspwikiApache JSPWiki up to 2.11.1

🔴Vulnerability Details

3
OSV
Cross Site Request Forgery in Apache JSPWiki2022-02-26
GHSA
Cross Site Request Forgery in Apache JSPWiki2022-02-26
CVEList
Apache JSPWiki CSRF Account Takeover2022-02-25
CVE-2022-24947 (HIGH CVSS 8.8) | Apache JSPWiki user preferences for | cvebase.io