PT-2020-14244 · Xwiki · Xwiki

Published

2020-09-10

·

Updated

2021-11-18

·

CVE-2020-15171

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 11.10.5 XWiki versions prior to 12.2.1
Description The issue allows any user with SCRIPT right (EDIT right before XWiki 7.4) to gain access to the application server Servlet context. This access contains tools that enable the instantiation of arbitrary Java objects and the invocation of methods, potentially leading to arbitrary code execution.
Recommendations For versions prior to 11.10.5, update to version 11.10.5 or later. For versions prior to 12.2.1, update to version 12.2.1 or later. As a temporary workaround, consider giving SCRIPT right only to trusted users to minimize the risk of exploitation.

Fix

Code Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15171
GHSA-7QW5-PQHC-XM4G

Affected Products

Xwiki