Описание
XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading.
Ссылки
- Patch
- Patch
- Patch
- ExploitVendor Advisory
- ExploitVendor Advisory
- Patch
- Patch
- Patch
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6.4 (включая) до 14.10.19 (исключая)Версия от 15.0 (включая) до 15.5.4 (исключая)Версия от 15.6 (включая) до 15.10 (исключая)
Одно из
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.33683
Средний
9.9 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-862
CWE-862
Связанные уязвимости
CVSS3: 9.9
github
почти 2 года назад
XWiki Platform remote code execution from account via custom skins support
EPSS
Процентиль: 97%
0.33683
Средний
9.9 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-862
CWE-862