Количество 3
Количество 3
CVE-2023-29518
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of `Invitation.InvitationCommon`. This page is installed by default. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. Users are advised to upgrade. There are no known workarounds for this issue.
GHSA-px54-3w5j-qjg9
XWiki Platform vulnerable to privilege escalation from view right using Invitation.InvitationCommon
BDU:2024-01263
Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki, существующая из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнять произвольный код Groovy, Python или Velocity
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-29518 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of `Invitation.InvitationCommon`. This page is installed by default. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. Users are advised to upgrade. There are no known workarounds for this issue. | CVSS3: 9.9 | 2% Низкий | почти 3 года назад | |
GHSA-px54-3w5j-qjg9 XWiki Platform vulnerable to privilege escalation from view right using Invitation.InvitationCommon | CVSS3: 8.8 | 2% Низкий | почти 3 года назад | |
BDU:2024-01263 Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki, существующая из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнять произвольный код Groovy, Python или Velocity | CVSS3: 8.8 | 2% Низкий | почти 3 года назад |
Уязвимостей на страницу