PT-2023-31148 · Xwiki · Xwiki Change Request

Michitux

·

Publicado

2023-12-04

·

Atualizado

2023-12-08

·

CVE-2023-49280

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Change Request versions prior to 1.10
Description The issue allows an attacker to obtain password hashes of users by editing user profiles and downloading the XML file created by the change request. This vulnerability impacts all versions of Change Request, but the impact depends on the rights set on the wiki, requiring the user to have the Change request right and view rights on the page to target. The issue cannot be easily exploited in an automated way.
Recommendations For versions prior to 1.10, upgrade to Change Request 1.10 to apply the patch that denies users the right to edit pages containing password fields with change requests. As a temporary workaround, consider denying the Change request right on some spaces, such as the XWiki space, which includes any user profile by default.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49280
GHSA-2FR7-CC7P-P45Q

Produtos afetados

Xwiki Change Request