8.8
CVSSv3

CVE-2022-24947

Published: 25/02/2022 Updated: 04/03/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache jspwiki

Mailing Lists

Severity Critical Vendor The Apache Software Foundation Versions Affected Apache JSPWiki up to 2111 Description Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover Mitigation Apache JSPWiki users should upgrade to 2112 or later Installations mitigate the issue Credit This issue was dis ...