PT-2020-14316 · Xwiki · Xwiki

Thomas Mortagne

·

Published

2020-10-16

·

Updated

2021-11-18

·

CVE-2020-15252

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 12.5 XWiki versions prior to 11.10.6
Description The issue allows any user with SCRIPT right (EDIT right before XWiki 7.4) to gain access to the application server Servlet context. This access contains tools that enable the instantiation of arbitrary Java objects and the invocation of methods, potentially leading to arbitrary code execution.
Recommendations For versions prior to 12.5, update to version 12.5 or later. For versions prior to 11.10.6, update to version 11.10.6 or later. As a temporary workaround, consider giving SCRIPT right only to trusted users.

Exploit

Fix

Code Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15252
GHSA-5HV6-MH8Q-Q9V8

Affected Products

Xwiki