Логотип exploitDog
bind:CVE-2023-29511
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-29511

Количество 2

Количество 2

nvd логотип

CVE-2023-29511

почти 3 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the section ids in `XWiki.AdminFieldsDisplaySheet`. This page is installed by default. The vulnerability has been patched in XWiki versions 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-rfh6-mg6h-h668

почти 3 года назад

xwiki-platform-administration-ui vulnerable to privilege escalation

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-29511

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the section ids in `XWiki.AdminFieldsDisplaySheet`. This page is installed by default. The vulnerability has been patched in XWiki versions 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.

CVSS3: 9.9
2%
Низкий
почти 3 года назад
github логотип
GHSA-rfh6-mg6h-h668

xwiki-platform-administration-ui vulnerable to privilege escalation

CVSS3: 9.9
2%
Низкий
почти 3 года назад

Уязвимостей на страницу