PT-2022-16128 · Xwiki · Xwiki Platform

Denis Gervalle

·

Published

2022-02-09

·

Updated

2022-02-16

·

CVE-2022-23615

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 13.0
Description The issue affects XWiki Platform, a generic wiki platform offering runtime services for applications built on top of it. In affected versions, any user with SCRIPT right can save a document with the right of the current user, allowing access to API requiring programming right if the current user has programming right.
Recommendations For versions prior to 13.0, update to XWiki 13.0 to resolve the issue. As a temporary workaround, consider limiting SCRIPT access to trusted users only.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23615
GHSA-F4CJ-3Q3H-884R

Affected Products

Xwiki Platform