CSRF Privilege Escalation in Apache JSPWiki <2.11.3 Image Plugin
CVE-2022-34158 Published on August 4, 2022

User Group Privilege Escalation
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.

NVD


Products Associated with CVE-2022-34158

Want to know whenever a new CVE is published for Apache JSPWiki? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache JSPWiki:

Exploit Probability

EPSS
1.09%
Percentile
77.72%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.