PT-2023-20663 · Unknown · Xwiki Platform

Michael Hamann

·

Published

2023-03-02

·

Updated

2023-03-13

·

CVE-2023-26472

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki Platform versions 6.2-milestone-1 through 14.8 XWiki Platform versions 14.4 through 14.4.5 XWiki Platform versions 13.10 through 13.10.9
Description XWiki Platform is a generic wiki platform where, starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even through the user profile for users not having edit right.
Recommendations For XWiki Platform versions 6.2-milestone-1 through 14.8, update to version 14.9 or later. For XWiki Platform versions 14.4 through 14.4.5, update to version 14.4.6 or later. For XWiki Platform versions 13.10 through 13.10.9, update to version 13.10.10 or later. As a temporary workaround, consider fixing the bug in the page IconThemesCode.IconThemeSheet by applying a modification from commit 48caf7491595238af2b531026a614221d5d61f38.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2023-26472
GHSA-VWR6-QP4Q-2WJ7

Affected Products

Xwiki Platform