8.8
CVSSv3

CVE-2022-34158

Published: 04/08/2022 Updated: 10/08/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki prior to 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache jspwiki