Логотип exploitDog
bind:CVE-2024-43401
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-43401

Количество 2

Количество 2

nvd логотип

CVE-2024-43401

больше 1 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-f963-4cq8-2gw7

больше 1 года назад

In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them

CVSS3: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-43401

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1.

CVSS3: 9
1%
Низкий
больше 1 года назад
github логотип
GHSA-f963-4cq8-2gw7

In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them

CVSS3: 9
1%
Низкий
больше 1 года назад

Уязвимостей на страницу