-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from UserPreferences.jsp processing user preference updates without CSRF protection. Since the CVE explicitly mentions UserPreferences.jsp as the attack vector and describes email modification via crafted requests, the form submission handler in this JSP file is the logical point of vulnerability. CSRF typically occurs when state-changing requests lack anti-CSRF tokens, which aligns with the described attack pattern. The high confidence comes from the direct reference to UserPreferences.jsp in all vulnerability descriptions and the clear CSRF mechanism (CWE-352) involved.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.jspwiki:jspwiki-main | maven | < 2.11.3 | 2.11.3 |
Ongoing coverage of React2Shell