Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qvp-39mm-95v8

Опубликовано: 07 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations

Impact

A user that doesn't have programming rights can execute arbitrary code when creating a page using the Migration Page template. A possible attack vector is the following:

  • Create a page and add the following content:
confluencepro.job.question.advanced.input={{/html}} {{async async="true" cached="false" context="doc.reference"}}{{groovy}}println("hello from groovy!"){{/groovy}}{{/async}}
  • Use the object editor to add an object of type XWiki.TranslationDocumentClass with scope USER.
  • Access an unexisting page using the MigrationTemplate
http://localhost:8080/xwiki/bin/edit/Page123?template=ConfluenceMigratorPro.Code.MigrationTemplate

It is expected that {{/html}} {{async async="true" cached="false" context="doc.reference"}}{{groovy}}println("hello from groovy!"){{/groovy}}{{/async}} will be present on the page, however, hello from groovy will be printed.

Patches

The issue will be fixed as part of v1.2. The fix was added with commit 35cef22

Workarounds

There are no known workarounds besides upgrading.

References

No references.

Пакеты

Наименование

com.xwiki.confluencepro:application-confluence-migrator-pro-ui

maven
Затронутые версииВерсия исправления

>= 1.0, < 1.2.0

1.2.0

EPSS

Процентиль: 63%
0.00459
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-95

Связанные уязвимости

CVSS3: 9.1
nvd
11 месяцев назад

XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0.

CVSS3: 9.1
fstec
11 месяцев назад

Уязвимость компонента Migration Page Template инструмента для миграции данных XWiki Confluence Migrator Pro, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 63%
0.00459
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-95