PT-2021-19813 · Xwiki · Xwiki Platform

Grigorii Liullin

·

Published

2021-05-18

·

Updated

2023-09-29

·

CVE-2021-32621

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 12.6.7 XWiki Platform versions prior to 12.10.3
Description A user without Script or Programming right is able to execute script requiring privileges by editing gadget titles in the dashboard.
Recommendations For versions prior to 12.6.7, upgrade to XWiki 12.6.7 or later. For versions prior to 12.10.3, upgrade to XWiki 12.10.3 or later. As a temporary workaround, consider restricting access to the dashboard gadget titles until a patch is applied.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-32621
GHSA-H353-HC43-95VC

Affected Products

Xwiki Platform