PT-2023-23581 · Unknown · Xwiki Platform
Paulos Mesfin
·
Published
2023-05-15
·
Updated
2023-05-24
·
CVE-2023-32068
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 14.10.4
Description
The XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4, it is possible to exploit well-known parameters in XWiki URLs to perform redirection to an untrusted site. This issue was partially fixed in the past for XWiki 12.10.7 and 13.3RC1, but there was still the possibility to force specific URLs to skip some checks. For example, using URLs like
http:example.com in the parameter would allow the redirect. The issue has now been patched against all patterns that are known for performing redirects.Recommendations
To resolve the issue, users are advised to upgrade to XWiki 14.10.4 or 15.0, as these versions have the patch for the vulnerability. There are no known workarounds for this issue other than upgrading.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform