HTTP: Apache JSPWiki UserPreferences.jsp Cross-Site Request Forgery

This signature detects attempts to exploit a known vulnerability against Apache JSPWiki. A successful attack can lead to security bypass.

Extended Description

A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.

Affected Products

Apache jspwiki

References

CVE: CVE-2022-28731

Short Name
HTTP:APACHE:JSPWIKI-USRPRF-CSRF
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apache CVE-2022-28731 Cross-Site Forgery JSPWiki Request UserPreferences.jsp
Release Date
10/20/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3619
False Positive
Unknown
Vendors

Apache

Found a potential security threat?