Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-34158: JSPWiki: CVE-2022-34158Cve=title

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker’s account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.

CVE
#csrf#vulnerability#apache#js

About cookies on this site#

This site uses cookie technology to store your user preferences to provide a more personalized browsing experience. No data will be shared by this site with 3rd parties. For more information on the cookies we use and how you can manage your cookie settings, please go to our Cookies Policy.

Ok, understood. Learn more …

Related news

GHSA-jp3m-p26h-mm7v: Apache JSPWiki CSRF due to crafted invocation on the Image plugin

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907