PT-2007-1499 · Xwiki · Xwiki

Publicado

2007-09-14

·

Atualizado

2022-05-01

·

CVE-2006-7223

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions XWiki versions 0.9.543 through 0.9.1252
Description The issue allows remote authenticated users without programming rights to execute arbitrary code. This is achieved by selecting a document whose author has programming rights, modifying the document to contain a script, and then previewing the document without saving it.
Recommendations For XWiki versions 0.9.543 through 0.9.1252, consider restricting access to the PreviewAction feature until a proper fix is applied, ensuring that only authorized users can preview documents, especially those with programming rights. Additionally, limit the ability to modify documents to only those users who have been explicitly granted programming rights.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-7223
GHSA-H5JM-JJGX-Q2WF

Produtos afetados

Xwiki