Логотип exploitDog
bind:CVE-2022-24898
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24898

Количество 2

Количество 2

nvd логотип

CVE-2022-24898

почти 4 года назад

org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service. The problem has been patched in versions 12.10.10, 13.4.4, and 13.8-rc-1. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-m2r5-4w96-qxg5

почти 4 года назад

Arbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xml

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24898

org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service. The problem has been patched in versions 12.10.10, 13.4.4, and 13.8-rc-1. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.

CVSS3: 4.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-m2r5-4w96-qxg5

Arbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xml

CVSS3: 4.9
0%
Низкий
почти 4 года назад

Уязвимостей на страницу