Логотип exploitDog
bind:CVE-2023-50721
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-50721

Количество 3

Количество 3

nvd логотип

CVE-2023-50721

около 2 лет назад

XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the injection of XWiki syntax containing script macros including Groovy macros that allow remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki instance. This attack can be executed by any user who can edit some wiki page like the user's profile (editable by default) as user interface extensions that will be displayed in the search administration can be added on any document by any user. The necessary escaping has been added in XWiki 14.10.15, 15.5.2 and 15.7RC1. As a workaround, the patch can be applied manually applied to the page `XWiki.SearchAdmin`.

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-7654-vfh6-rw6x

около 2 лет назад

Remote code execution from account through SearchAdmin

CVSS3: 9.9
EPSS: Средний
fstec логотип

BDU:2024-00229

около 2 лет назад

Уязвимость пользовательского интерфейса поиска платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.9
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-50721

XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the injection of XWiki syntax containing script macros including Groovy macros that allow remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki instance. This attack can be executed by any user who can edit some wiki page like the user's profile (editable by default) as user interface extensions that will be displayed in the search administration can be added on any document by any user. The necessary escaping has been added in XWiki 14.10.15, 15.5.2 and 15.7RC1. As a workaround, the patch can be applied manually applied to the page `XWiki.SearchAdmin`.

CVSS3: 9.9
43%
Средний
около 2 лет назад
github логотип
GHSA-7654-vfh6-rw6x

Remote code execution from account through SearchAdmin

CVSS3: 9.9
43%
Средний
около 2 лет назад
fstec логотип
BDU:2024-00229

Уязвимость пользовательского интерфейса поиска платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.9
43%
Средний
около 2 лет назад

Уязвимостей на страницу