Description
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
Remediation
References
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732
Related Vulnerabilities
CVE-2019-10378 Vulnerability in maven package org.jenkins-ci.plugins:testlink
CVE-2017-16897 Vulnerability in npm package passport-wsfed-saml2
CVE-2023-50775 Vulnerability in maven package org.jenkins-ci.plugins:ec2-deployment-dashboard
CVE-2021-26272 Vulnerability in npm package ckeditor4-dev
CVE-2021-21685 Vulnerability in maven package org.jenkins-ci.main:jenkins-core