Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h5jm-jjgx-q2wf

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью

Описание

XWiki Remote Code Execution

PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 0.9.543, <= 0.9.1252

1.0B1

EPSS

Процентиль: 61%
0.00418
Низкий

Связанные уязвимости

nvd
больше 18 лет назад

PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.

EPSS

Процентиль: 61%
0.00418
Низкий