Логотип exploitDog
bind:CVE-2023-29206
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-29206

Количество 2

Количество 2

nvd логотип

CVE-2023-29206

почти 3 года назад

XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object and to craft a script allowing to perform some operations when executing by a user with appropriate rights. This has been patched in XWiki 14.9-rc-1 by only executing the script if the author of it has Script rights.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-cmvg-w72j-7phx

почти 3 года назад

org.xwiki.platform:xwiki-platform-skin-skinx vulnerable to basic Cross-site Scripting by exploiting JSX or SSX plugins

CVSS3: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-29206

XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object and to craft a script allowing to perform some operations when executing by a user with appropriate rights. This has been patched in XWiki 14.9-rc-1 by only executing the script if the author of it has Script rights.

CVSS3: 9
6%
Низкий
почти 3 года назад
github логотип
GHSA-cmvg-w72j-7phx

org.xwiki.platform:xwiki-platform-skin-skinx vulnerable to basic Cross-site Scripting by exploiting JSX or SSX plugins

CVSS3: 9
6%
Низкий
почти 3 года назад

Уязвимостей на страницу