Description
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or later.
Remediation
References
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732
Related Vulnerabilities
CVE-2019-10279 Vulnerability in maven package org.jenkins-ci.plugins:jenkins-reviewbot
CVE-2021-25122 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-37961 Vulnerability in maven package org.jenkins-ci.plugins:assembla-auth
CVE-2019-10453 Vulnerability in maven package org.jenkins-ci.plugins:delphix
CVE-2017-7678 Vulnerability in maven package org.apache.spark:spark-core_2.11