Логотип exploitDog
bind:CVE-2022-24821
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24821

Количество 2

Количество 2

nvd логотип

CVE-2022-24821

почти 4 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-ghcq-472w-vf4h

почти 4 года назад

Incorrect Use of Privileged APIs in org.xwiki.platform.skin.skinx

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24821

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.

CVSS3: 6.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-ghcq-472w-vf4h

Incorrect Use of Privileged APIs in org.xwiki.platform.skin.skinx

CVSS3: 6.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу