Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr59-gm53-v7cq

Опубликовано: 24 июл. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.3

Описание

XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter

Impact

It's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value.

One can see the result of the injection with http://127.0.0.1:8080/xwiki/rest/liveData/sources/liveTable/entries?sourceParams.template=getdeleteddocuments.vm&sort=injected (this example does not work, but it shows that an HQL query was executed with the passed value which look nothing like an order by value, without any kind of sanitation).

Patches

This has been patched in 17.3.0-rc-1, 16.10.6.

Workarounds

There is no known workaround, other than upgrading XWiki.

References

https://jira.xwiki.org/browse/XWIKI-23093

For more information

If you have any questions or comments about this advisory:

Attribution

The vulnerability was identifier by Aleksey Solovev from Positive Technologies.

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-distribution-war

maven
Затронутые версииВерсия исправления

>= 9.4-rc-1, < 16.10.6

16.10.6

Наименование

org.xwiki.platform:xwiki-platform-distribution-war

maven
Затронутые версииВерсия исправления

>= 17.0.0-rc-1, < 17.3.0-rc-1

17.3.0-rc-1

EPSS

Процентиль: 63%
0.00463
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
23 дня назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.

CVSS3: 9.8
fstec
4 месяца назад

Уязвимость шаблона getdeleteddocuments.vm платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 63%
0.00463
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89