 
                        We found results for “”
CVE-2023-46743
Date: November 9, 2023
application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on the rights that a user has over a document, they should be able to open the office attachments files in view or edit mode. Currently, if a user opens an attachment file in edit mode in collabora, this right will be preserved for all future users, until the editing session is closes, even if some of them have only view right. Collabora server is the one issuing this request and it seems that the "userCanWrite" query parameter is cached, even if, for example, token is not. This issue has been patched in version 1.3.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Incorrect Default Permissions
CWE-276CVSS v3.1
| Base Score: |  | 
|---|---|
| Attack Vector (AV): | PHYSICAL | 
| Attack Complexity (AC): | LOW | 
| Privileges Required (PR): | NONE | 
| User Interaction (UI): | REQUIRED | 
| Scope (S): | CHANGED | 
| Confidentiality (C): | HIGH | 
| Integrity (I): | HIGH | 
| Availability (A): | HIGH | 
 Vulnerabilities
                        Vulnerabilities
                 Projects
                        Projects
                 Vulnerability Disclosure
                        Vulnerability Disclosure
                 About Us
                    About Us
                 Contact Us
                    Contact Us
                

