PT-2023-23581 · Unknown · Xwiki Platform

Paulos Mesfin

·

Published

2023-05-15

·

Updated

2023-05-24

·

CVE-2023-32068

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 14.10.4
Description The XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4, it is possible to exploit well-known parameters in XWiki URLs to perform redirection to an untrusted site. This issue was partially fixed in the past for XWiki 12.10.7 and 13.3RC1, but there was still the possibility to force specific URLs to skip some checks. For example, using URLs like http:example.com in the parameter would allow the redirect. The issue has now been patched against all patterns that are known for performing redirects.
Recommendations To resolve the issue, users are advised to upgrade to XWiki 14.10.4 or 15.0, as these versions have the patch for the vulnerability. There are no known workarounds for this issue other than upgrading.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-32068
GHSA-6GVJ-8VC5-8V3J

Affected Products

Xwiki Platform