CVE-2022-24947

Description

Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.846

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-24947,CVE-2022-24948 are fixed in Apache-jspwiki-main 2.11.2Windows
Vulnerabilities CVE-2022-24947,CVE-2022-24948 are fixed in Apache-jspwiki-main for Linux 2.11.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234