Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp3m-p26h-mm7v

Опубликовано: 05 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Apache JSPWiki CSRF due to crafted invocation on the Image plugin

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.

Пакеты

Наименование

org.apache.jspwiki:jspwiki-main

maven
Затронутые версииВерсия исправления

< 2.11.3

2.11.3

EPSS

Процентиль: 78%
0.01087
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.

CVSS3: 8.8
nvd
больше 3 лет назад

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.

CVSS3: 8.8
debian
больше 3 лет назад

A carefully crafted invocation on the Image plugin could trigger an CS ...

EPSS

Процентиль: 78%
0.01087
Низкий

8.8 High

CVSS3

Дефекты

CWE-352