PT-2022-16130 · Xwiki · Xwiki Platform
Tmortagne
·
Published
2022-02-09
·
Updated
2022-02-15
·
CVE-2022-23617
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 12.10.6
XWiki Platform versions prior to 13.2CR1
Description
The issue allows any user with edit rights to copy the content of a page they do not have access to by using it as a template for a new page. There are no known workarounds for this issue.
Recommendations
For versions prior to 12.10.6, update to version 12.10.6 or later.
For versions prior to 13.2CR1, update to version 13.2CR1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform