Medium severity6.5NVD Advisory· Published Aug 4, 2022· Updated Jun 17, 2026
CVE-2022-28731
CVE-2022-28731
Description
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.jspwiki:jspwiki-mainMaven | < 2.11.3 | 2.11.3 |
Affected products
3- Apache Software Foundation/Apache JSPWikiv5Range: Apache JSPWiki
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-9x9j-vrhj-v364ghsaADVISORY
- jspwiki-wiki.apache.org/Wiki.jspnvdNot ApplicableVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-28731ghsaADVISORY
News mentions
0No linked articles in our index yet.