Логотип exploitDog
bind:CVE-2022-41937
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-41937

Количество 2

Количество 2

nvd логотип

CVE-2022-41937

около 3 лет назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and 13.10.8. As a workaround, setting the right of the page Filter.WebHome and making sure only the main wiki administrators can view the application installed on main wiki or edit the page and apply the changed described in commit fb49b4f.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-q6jp-gcww-8v2j

около 3 лет назад

Missing Authorization in Filter Stream Converter Application of XWiki-platform

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-41937

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and 13.10.8. As a workaround, setting the right of the page Filter.WebHome and making sure only the main wiki administrators can view the application installed on main wiki or edit the page and apply the changed described in commit fb49b4f.

CVSS3: 9.6
10%
Низкий
около 3 лет назад
github логотип
GHSA-q6jp-gcww-8v2j

Missing Authorization in Filter Stream Converter Application of XWiki-platform

CVSS3: 9.6
10%
Низкий
около 3 лет назад

Уязвимостей на страницу