PT-2023-20455 · Xwiki · Xwiki Commons

·

CVE-2023-26055

·

Publicado

2023-03-01

·

Atualizado

2023-03-13

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki Commons versions 3.1-milestone-1 through 13.10.8 XWiki Commons versions 14.0.0 through 14.4.3 XWiki Commons versions 14.5.0 through 14.7RC0
Description The issue allows any user to edit their own profile and inject code, which is executed with programming rights. This can also be exploited in other places where short text properties are displayed, such as in apps created using Apps Within Minutes that use a short text field.
Recommendations For versions 3.1-milestone-1 through 13.10.8, update to version 13.10.9 or later. For versions 14.0.0 through 14.4.3, update to version 14.4.4 or later. For versions 14.5.0 through 14.7RC0, update to version 14.7RC1 or later. As a temporary workaround, consider restricting access to short text properties until a patch is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26055
GHSA-8CW6-4R32-6R3H

Produtos afetados

Xwiki Commons