Логотип exploitDog
bind:CVE-2023-29209
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-29209

Количество 3

Количество 3

nvd логотип

CVE-2023-29209

почти 3 года назад

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the macro parameters of the legacy notification activity macro. This macro is installed by default in XWiki. The vulnerability can be exploited via every wiki page that is editable including the user's profile, but also with just view rights using the HTMLConverter that is part of the CKEditor integration which is bundled with XWiki. The vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-9pc2-x9qf-7j2q

почти 3 года назад

org.xwiki.platform:xwiki-platform-legacy-notification-activitymacro Eval Injection vulnerability

CVSS3: 9.9
EPSS: Низкий
fstec логотип

BDU:2023-05268

почти 3 года назад

Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki, связанная с непринятием мер по нейтрализации инструкций в динамически исполняемом коде, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-29209

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the macro parameters of the legacy notification activity macro. This macro is installed by default in XWiki. The vulnerability can be exploited via every wiki page that is editable including the user's profile, but also with just view rights using the HTMLConverter that is part of the CKEditor integration which is bundled with XWiki. The vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10.

CVSS3: 9.9
2%
Низкий
почти 3 года назад
github логотип
GHSA-9pc2-x9qf-7j2q

org.xwiki.platform:xwiki-platform-legacy-notification-activitymacro Eval Injection vulnerability

CVSS3: 9.9
2%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-05268

Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki, связанная с непринятием мер по нейтрализации инструкций в динамически исполняемом коде, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
2%
Низкий
почти 3 года назад

Уязвимостей на страницу