PT-2020-14244 · Xwiki · Xwiki
Published
2020-09-10
·
Updated
2021-11-18
·
CVE-2020-15171
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki versions prior to 11.10.5
XWiki versions prior to 12.2.1
Description
The issue allows any user with SCRIPT right (EDIT right before XWiki 7.4) to gain access to the application server Servlet context. This access contains tools that enable the instantiation of arbitrary Java objects and the invocation of methods, potentially leading to arbitrary code execution.
Recommendations
For versions prior to 11.10.5, update to version 11.10.5 or later.
For versions prior to 12.2.1, update to version 12.2.1 or later.
As a temporary workaround, consider giving SCRIPT right only to trusted users to minimize the risk of exploitation.
Fix
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki