CVE-2022-24948: Apache JSPWiki preauth Stored XSS to ATO
pwn.ai | vulnerability | CVE-2022-24948 | #vulnerability-research | #account-takeover | #stored-xss | #jspwiki | #cve-2022-24948
Summary
CVE-2022-24948: how a tricky stored XSS in JSPWiki's username field was exploited via a meta-tag focus trick that avoids colons, escalating pre-auth injection toward account takeover.
- CVE
- CVE-2022-24948
- Published
- Collected
Skip to content