
We found results for “”
CVE-2023-29211
Good to know:

Date: April 16, 2023
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights "WikiManager.DeleteWiki" can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the "wikiId" url parameter. The problem has been patched on XWiki 13.10.11, 14.4.7, and 14.10.
Language: Java
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Top Fix

Upgrade Version
Upgrade to version org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki:13.10.11;org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki:14.4.7;org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki:14.10
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |