« Volver al listado

CVE-2022-28732

Estado: ModificadaMedia (6.1)—

A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or later.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-28732",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache JSPWiki",
          "versions": [
            {
              "status": "affected",
              "version": "Apache JSPWiki",
              "versionType": "custom",
              "lessThanOrEqual": "Apache JSPWiki up to 2.11.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-04T07:15:07.597",
  "references": [
    {
      "url": "https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or later."
    },
    {
      "lang": "es",
      "value": "Una petición cuidadosamente diseñada en WeblogPlugin podría desencadenar una vulnerabilidad de tipo XSS en Apache JSPWiki, que podría permitir al atacante ejecutar javascript en el navegador de la víctima y conseguir información confidencial sobre la misma. Los usuarios de Apache JSPWiki deberían actualizar a la versión 2.11.3 o posterior"
    }
  ],
  "lastModified": "2026-06-17T04:38:56.103",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64A3E769-A3E7-4648-8792-5138BD591C1F",
              "versionEndExcluding": "2.11.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}