PT-2022-26159 · Xwiki · Xwiki-Platform-Oldcore

Simon Urli

·

Published

2022-11-21

·

Updated

2022-11-30

·

CVE-2022-41929

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions xwiki-platform-oldcore versions prior to 13.10.7 xwiki-platform-oldcore versions prior to 14.4.2 xwiki-platform-oldcore versions prior to 14.5RC1
Description The issue is related to missing authorization in the setDisabledStatus method of the User class, allowing users with only Script rights to enable or disable other users. This operation should be restricted to users with admin rights.
Recommendations For versions prior to 13.10.7, update to version 13.10.7 or later. For versions prior to 14.4.2, update to version 14.4.2 or later. For versions prior to 14.5RC1, update to version 14.5RC1 or later. As a temporary workaround, consider restricting Script rights to trusted users until the issue is resolved.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-41929
GHSA-2GJ2-VJ98-J2QQ

Affected Products

Xwiki-Platform-Oldcore