CVE-2022-46907
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/jspwiki
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2023/05/25/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/1m0mkq2nttx8tn94m11mytn4f0tv1504Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/05/25/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/1m0mkq2nttx8tn94m11mytn4f0tv1504Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.