← Back to CVE List

CVE-2022-28731

Published: 2022-08-04T07:15Z
Last Modified: 2024-11-21T06:57Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt