PT-2022-16128 · Xwiki · Xwiki Platform
Denis Gervalle
·
Published
2022-02-09
·
Updated
2022-02-16
·
CVE-2022-23615
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 13.0
Description
The issue affects XWiki Platform, a generic wiki platform offering runtime services for applications built on top of it. In affected versions, any user with SCRIPT right can save a document with the right of the current user, allowing access to API requiring programming right if the current user has programming right.
Recommendations
For versions prior to 13.0, update to XWiki 13.0 to resolve the issue.
As a temporary workaround, consider limiting SCRIPT access to trusted users only.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform