Логотип exploitDog
bind:CVE-2022-41927
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-41927

Количество 2

Количество 2

nvd логотип

CVE-2022-41927

около 3 лет назад

XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to patch existing instances directly by editing the page Main.Tags and add this kind of check, in the code for renaming and for deleting: ``` #if (!$services.csrf.isTokenValid($request.get('form_token'))) #set ($discard = $response.sendError(401, "Wrong CSRF token")) #end ```

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-mq7h-5574-hw9f

около 3 лет назад

Cross-Site Request Forgery (CSRF) allowing to delete or rename tags

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-41927

XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to patch existing instances directly by editing the page Main.Tags and add this kind of check, in the code for renaming and for deleting: ``` #if (!$services.csrf.isTokenValid($request.get('form_token'))) #set ($discard = $response.sendError(401, "Wrong CSRF token")) #end ```

CVSS3: 7.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-mq7h-5574-hw9f

Cross-Site Request Forgery (CSRF) allowing to delete or rename tags

CVSS3: 7.4
1%
Низкий
около 3 лет назад

Уязвимостей на страницу