Логотип exploitDog
bind:CVE-2023-29515
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-29515

Количество 2

Количество 2

nvd логотип

CVE-2023-29515

почти 3 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can create a space can become admin of that space through App Within Minutes. The admin right implies the script right and thus allows JavaScript injection. The vulnerability can be exploited by creating an app in App Within Minutes. If the button should be disabled because the user doesn't have global edit right, the app can also be created by directly opening `/xwiki/bin/view/AppWithinMinutes/CreateApplication?wizard=true` on the XWiki installation. This has been patched in XWiki 13.10.11, 14.4.8, 14.10.1 and 15.0 RC1 by not granting the space admin right if the user doesn't have script right on the space where the app is created. Error message are displayed to warn the user that the app will be broken in this case. Users who became space admin through this vulnerability won't loose the space admin right due to the fix, so it is advised to check if all users who creat

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-44h9-xxvx-pg6x

почти 3 года назад

XWiki App Within Minutes app grants space admin rights that allows cross-site scripting

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-29515

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can create a space can become admin of that space through App Within Minutes. The admin right implies the script right and thus allows JavaScript injection. The vulnerability can be exploited by creating an app in App Within Minutes. If the button should be disabled because the user doesn't have global edit right, the app can also be created by directly opening `/xwiki/bin/view/AppWithinMinutes/CreateApplication?wizard=true` on the XWiki installation. This has been patched in XWiki 13.10.11, 14.4.8, 14.10.1 and 15.0 RC1 by not granting the space admin right if the user doesn't have script right on the space where the app is created. Error message are displayed to warn the user that the app will be broken in this case. Users who became space admin through this vulnerability won't loose the space admin right due to the fix, so it is advised to check if all users who creat

CVSS3: 7.7
1%
Низкий
почти 3 года назад
github логотип
GHSA-44h9-xxvx-pg6x

XWiki App Within Minutes app grants space admin rights that allows cross-site scripting

CVSS3: 5.4
1%
Низкий
почти 3 года назад

Уязвимостей на страницу