Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6mf5-36v9-3h2w

Опубликовано: 20 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.9

Описание

XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application

Impact

Any user with view rights on any document can execute code with programming rights, leading to remote code execution by crafting an url with a dangerous payload. See the example below: Open <xwiki-host>/xwiki/bin/view/%5D%5D%20%7B%7Basync%20async%3D%22true%22%20cached%3D%22false%22%20context%3D%22doc.reference%22%7D%7D%7B%7Bgroovy%7D%7Dprintln(%22Hello%20%22%20%2B%20%22from%20groovy!%22)%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D?sheet=Invitation.InvitationGuestActions&xpage=view where <xwiki-host> is the URL of your XWiki installation.

Patches

The problem as been patching on XWiki 15.0, 14.10.4 and 14.4.8.

Workarounds

It is possible to partially fix the issue by applying this patch. Note that some additional issue can remain and can be fixed automatically by a migration. Hence, it is advised to upgrade to one of the patched version instead of patching manually.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-invitation-ui

maven
Затронутые версииВерсия исправления

>= 2.4-m-2, < 14.4.8

14.4.8

Наименование

org.xwiki.platform:xwiki-platform-invitation-ui

maven
Затронутые версииВерсия исправления

>= 14.5, < 14.10.4

14.10.4

Наименование

org.xwiki.platform:xwiki-platform-invitation-ui

maven
Затронутые версииВерсия исправления

>= 15.0-rc-1, < 15.0

15.0

EPSS

Процентиль: 97%
0.3348
Средний

9.9 Critical

CVSS3

Дефекты

CWE-94
CWE-95

Связанные уязвимости

CVSS3: 9.9
nvd
больше 2 лет назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to remote code execution by crafting an url with a dangerous payload. The problem has been patched in XWiki 15.0, 14.10.4 and 14.4.8.

CVSS3: 8
fstec
больше 2 лет назад

Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki , связанная с непринятием мер по нейтрализации инструкций в динамически исполняемом коде, позволяющая нарушителю выполнить произвольный код с root-привилегиями

EPSS

Процентиль: 97%
0.3348
Средний

9.9 Critical

CVSS3

Дефекты

CWE-94
CWE-95