CVE-2022-28731: Apache JSPWiki CSRF due to crafted request on UserPreferences.jsp
6.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.95073%
CWE
Published
8/5/2022
Updated
1/31/2023
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.jspwiki:jspwiki-main | maven | < 2.11.3 | 2.11.3 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from UserPreferences.jsp processing user preference updates without CSRF protection. Since the CVE explicitly mentions UserPreferences.jsp as the attack vector and describes email modification via crafted requests, the form submission handler in this JSP file is the logical point of vulnerability. CSRF typically occurs when state-changing requests lack anti-CSRF tokens, which aligns with the described attack pattern. The high confidence comes from the direct reference to UserPreferences.jsp in all vulnerability descriptions and the clear CSRF mechanism (CWE-352) involved.