PT-2022-16901 · Unknown · Xwiki Platform

Simon Urli

·

Published

2022-04-08

·

Updated

2022-04-15

·

CVE-2022-24821

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 12.10.11 XWiki Platform versions prior to 13.4.6 XWiki Platform versions prior to 13.10-rc-1
Description The issue allows simple users to create global SSX/JSX without specific rights. In theory, only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. However, a bug enables anyone with edit rights to create those.
Recommendations For versions prior to 12.10.11, upgrade to version 12.10.11 or later. For versions prior to 13.4.6, upgrade to version 13.4.6 or later. For versions prior to 13.10-rc-1, upgrade to version 13.10-rc-1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24821
GHSA-GHCQ-472W-VF4H

Affected Products

Xwiki Platform