PT-2022-16901 · Unknown · Xwiki Platform
Simon Urli
·
Published
2022-04-08
·
Updated
2022-04-15
·
CVE-2022-24821
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 12.10.11
XWiki Platform versions prior to 13.4.6
XWiki Platform versions prior to 13.10-rc-1
Description
The issue allows simple users to create global SSX/JSX without specific rights. In theory, only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. However, a bug enables anyone with edit rights to create those.
Recommendations
For versions prior to 12.10.11, upgrade to version 12.10.11 or later.
For versions prior to 13.4.6, upgrade to version 13.4.6 or later.
For versions prior to 13.10-rc-1, upgrade to version 13.10-rc-1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform