Vulnerability record · CVE-2022-28730 · published 4 August 2022
CVE-2022-28730: Apache JSPWiki AJAXPreview.jsp reflected XSS via Denounce plugin
Apache · Jspwiki
Apache JSPWiki's AJAXPreview.jsp renders user-supplied URLs through the Denounce plugin without adequate sanitisation, allowing reflected cross-site scripting. The flaw is an incomplete fix for CVE-2021-40369, so sites that applied that earlier patch remain exposed. It matters because an attacker can run script in a victim's browser session and read sensitive information from the page.
Description
A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This vulnerability leverages CVE-2021-40369, where the Denounce plugin dangerously renders user-supplied URLs. Upon re-testing CVE-2021-40369, it appears that the patch was incomplete as it was still possible to insert malicious input via the Denounce plugin. Apache JSPWiki users should upgrade to 2.11.3 or later.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is a network-reachable XSS with a very high EPSS score, though it requires user interaction and no KEV listing or confirmed public exploit is present.
What it is
Apache JSPWiki's AJAXPreview.jsp renders user-supplied URLs through the Denounce plugin without adequate sanitisation, allowing reflected cross-site scripting. The flaw is an incomplete fix for CVE-2021-40369, so sites that applied that earlier patch remain exposed. It matters because an attacker can run script in a victim's browser session and read sensitive information from the page.
Impact
An attacker can execute JavaScript in a victim's browser in the context of the JSPWiki site, exposing session data and other sensitive information visible to that user. The CVSS scope change (S:C) means the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through a crafted request to AJAXPreview.jsp; the vector shows no privileges required (PR:N) but user interaction is required (UI:R), so a victim must follow a crafted link or otherwise trigger the request.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.854, 99.7th percentile), indicating substantial predicted exploitation activity. The only references are vendor advisories, so no public exploit code is confirmed by this record.
What to do
- Upgrade Apache JSPWiki to 2.11.3 or later, which the vendor states resolves the incomplete Denounce plugin fix.
- If immediate upgrade is not possible, restrict or disable the Denounce plugin and review any custom URL-rendering paths.
- Apply output encoding and URL sanitisation to all user-supplied input rendered by JSPWiki plugins.
- Deploy a WAF rule or CSP that blocks inline script execution on JSPWiki pages as a compensating control.
Detection
- Inspect web logs for requests to AJAXPreview.jsp containing script tags, event handlers, or javascript: URIs in parameters.
- Monitor for reflected payloads in HTTP responses from JSPWiki endpoints and alert on unencoded script content.
- Review browser or proxy telemetry for outbound requests or cookie access originating from JSPWiki pages shortly after a crafted link is opened.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732 | Vendor Advisory |
| https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-28732 | Vendor Advisory |
Track CVE-2022-28730 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-28730), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.