Описание
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their first name field and see it executed with programming rights. Leading to rights escalation. The vulnerability has been fixed on XWiki 14.4.8, 14.10.6, and 15.1. As a workaround, one may apply the patch manually.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
- PatchVendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
9.9 Critical
CVSS3
8.8 High
CVSS3
Дефекты
Связанные уязвимости
XWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResults
Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki , связанная с непринятием мер по нейтрализации инструкций в динамически исполняемом коде, позволяющая нарушителю повысить свои привилегии
EPSS
9.9 Critical
CVSS3
8.8 High
CVSS3