Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hjg-cghv-22ww

Опубликовано: 20 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection

Impact

A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a gadget of their own dashboard. Note that the vulnerability does not impact comments of a wiki.

Patches

The vulnerability has been patched in XWiki 13.10.11, 14.4.8, 14.10.2, 15.0-rc-1.

Workarounds

The problem can be worked around by applying following changes directly in XWiki.AttachmentSelector page: https://github.com/xwiki/xwiki-platform/commit/5e8725b4272cd3e5be09d3ca84273be2da6869c1.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-attachment-ui

maven
Затронутые версииВерсия исправления

>= 3.0-rc-1, < 13.10.11

13.10.11

Наименование

org.xwiki.platform:xwiki-platform-attachment-ui

maven
Затронутые версииВерсия исправления

>= 14.0-rc-1, < 14.4.8

14.4.8

Наименование

org.xwiki.platform:xwiki-platform-attachment-ui

maven
Затронутые версииВерсия исправления

>= 14.5, < 14.10.2

14.10.2

EPSS

Процентиль: 95%
0.16098
Средний

8.8 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9
nvd
почти 3 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a gadget of their own dashboard. Note that the vulnerability does not impact comments of a wiki. The vulnerability has been patched in XWiki 13.10.11, 14.4.8, 14.10.2, 15.0-rc-1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 9
fstec
почти 3 года назад

Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki существует из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 95%
0.16098
Средний

8.8 High

CVSS3

Дефекты

CWE-74