PT-2022-16134 · Unknown · Xwiki Platform

·

CVE-2022-23620

·

Published

2022-02-09

·

Updated

2023-06-27

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 13.6-rc-1
Description The issue arises from the AbstractSxExportURLFactoryActionHandler#processSx function not properly escaping SSX document references when serializing them on the filesystem. This allows the HTML export process to contain reference elements with filesystem syntax like "../", "./", or "/" in general, which can lead to security issues. The referenced elements are not properly escaped.
Recommendations For versions prior to 13.6-rc-1, update to version 13.6-rc-1 to resolve the issue. As a temporary workaround, consider limiting or disabling document export to minimize the risk of exploitation. Additionally, giving script or subwiki admin rights only to trusted people and disabling HTML/PDF export can be done as a workaround until the issue is resolved.

Exploit

Fix

DoS

Path traversal

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23620
GHSA-7PH6-5CMQ-XGJQ

Affected Products

Xwiki Platform