PT-2023-31148 · Xwiki · Xwiki Change Request
Michitux
·
Publicado
2023-12-04
·
Atualizado
2023-12-08
·
CVE-2023-49280
CVSS v3.1
7.7
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Change Request versions prior to 1.10
Description
The issue allows an attacker to obtain password hashes of users by editing user profiles and downloading the XML file created by the change request. This vulnerability impacts all versions of Change Request, but the impact depends on the rights set on the wiki, requiring the user to have the Change request right and view rights on the page to target. The issue cannot be easily exploited in an automated way.
Recommendations
For versions prior to 1.10, upgrade to Change Request 1.10 to apply the patch that denies users the right to edit pages containing password fields with change requests.
As a temporary workaround, consider denying the Change request right on some spaces, such as the XWiki space, which includes any user profile by default.
Exploit
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Xwiki Change Request