Описание
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 12.6.7 and 12.10.3, a user without Script or Programming right is able to execute script requiring privileges by editing gadget titles in the dashboard. The issue has been patched in XWiki 12.6.7, 12.10.3 and 13.0RC1.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.0.1 (включая) до 12.6.7 (исключая)Версия от 12.10 (включая) до 12.10.3 (исключая)
Одно из
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:3.0:-:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:3.0:milestone3:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:3.0:rc1:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00691
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 8.8
github
больше 4 лет назад
Script injection without script or programming rights through Gadget titles
EPSS
Процентиль: 71%
0.00691
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-94