PT-2023-20663 · Unknown · Xwiki Platform
Michael Hamann
·
Published
2023-03-02
·
Updated
2023-03-13
·
CVE-2023-26472
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions 6.2-milestone-1 through 14.8
XWiki Platform versions 14.4 through 14.4.5
XWiki Platform versions 13.10 through 13.10.9
Description
XWiki Platform is a generic wiki platform where, starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even through the user profile for users not having edit right.
Recommendations
For XWiki Platform versions 6.2-milestone-1 through 14.8, update to version 14.9 or later.
For XWiki Platform versions 14.4 through 14.4.5, update to version 14.4.6 or later.
For XWiki Platform versions 13.10 through 13.10.9, update to version 13.10.10 or later.
As a temporary workaround, consider fixing the bug in the page
IconThemesCode.IconThemeSheet by applying a modification from commit 48caf7491595238af2b531026a614221d5d61f38.Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform