Description
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
Remediation
References
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732
Related Vulnerabilities
CVE-2023-28427 Vulnerability in npm package matrix-js-sdk
CVE-2020-2301 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2014-4671 Vulnerability in npm package hapi
CVE-2023-39152 Vulnerability in maven package org.jenkins-ci.plugins:gradle
CVE-2012-5885 Vulnerability in maven package tomcat:catalina