PT-2023-4819 · Xwiki · Xwiki

·

CVE-2023-36471

·

Publicado

2023-06-29

·

Atualizado

2023-07-10

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XWiki versions 14.6RC1 through 14.10.5 XWiki versions prior to 15.2RC1
Description The issue arises from the HTML sanitizer in XWiki, which allowed form and input HTML tags since version 14.6RC1. This enables an attacker without script right to create forms for phishing attacks or add inputs that allow remote code execution when submitted by an admin. The attacker must ensure the edit form appears plausible, which can be challenging without script right.
Recommendations For XWiki versions 14.6RC1 through 14.10.5, upgrade to version 14.10.6. For XWiki versions prior to 15.2RC1, upgrade to version 15.2RC1. As a temporary workaround, an admin can manually disallow the tags by adding form, input, select, textarea, button to the configuration option xml.htmlElementSanitizer.forbidTags in the xwiki.properties configuration file.

Exploit

Correção

Special Elements Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05282
CVE-2023-36471
GHSA-6PQF-C99P-758V

Produtos afetados

Xwiki