PT-2023-31148 · Xwiki · Xwiki Change Request

Michitux

·

Published

2023-12-04

·

Updated

2023-12-08

·

CVE-2023-49280

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Change Request versions prior to 1.10
Description The issue allows an attacker to obtain password hashes of users by editing user profiles and downloading the XML file created by the change request. This vulnerability impacts all versions of Change Request, but the impact depends on the rights set on the wiki, requiring the user to have the Change request right and view rights on the page to target. The issue cannot be easily exploited in an automated way.
Recommendations For versions prior to 1.10, upgrade to Change Request 1.10 to apply the patch that denies users the right to edit pages containing password fields with change requests. As a temporary workaround, consider denying the Change request right on some spaces, such as the XWiki space, which includes any user profile by default.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49280
GHSA-2FR7-CC7P-P45Q

Affected Products

Xwiki Change Request