Description
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or later.
Remediation
References
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732
Related Vulnerabilities
CVE-2022-43414 Vulnerability in maven package org.jenkins-ci.plugins:nunit
CVE-2014-0193 Vulnerability in maven package org.onosproject:onlab-stc
CVE-2022-41226 Vulnerability in maven package com.compuware.jenkins:compuware-common-configuration
CVE-2016-5007 Vulnerability in maven package org.springframework:spring-webmvc