PT-2020-14316 · Xwiki · Xwiki
Thomas Mortagne
·
Published
2020-10-16
·
Updated
2021-11-18
·
CVE-2020-15252
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
XWiki versions prior to 12.5
XWiki versions prior to 11.10.6
Description
The issue allows any user with SCRIPT right (EDIT right before XWiki 7.4) to gain access to the application server Servlet context. This access contains tools that enable the instantiation of arbitrary Java objects and the invocation of methods, potentially leading to arbitrary code execution.
Recommendations
For versions prior to 12.5, update to version 12.5 or later.
For versions prior to 11.10.6, update to version 11.10.6 or later.
As a temporary workaround, consider giving SCRIPT right only to trusted users.
Exploit
Fix
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki