PT-2023-4802 · Unknown · Ckeditor Integration Ui+1

Michael Hamann

·

Published

2023-01-04

·

Updated

2023-01-10

·

CVE-2023-22457

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CKEditor Integration UI versions prior to 1.64.3 XWiki Platform versions prior to 14.6 RC1
Description The issue is related to insufficient authentication checks for executed requests in the CKEditor integration interface of the XWiki platform. This allows an attacker to execute a Cross-Site Request Forgery (CSRF) attack, potentially leading to arbitrary remote code execution. If a privileged user with programming rights is tricked into executing a GET request to the CKEditor.HTMLConverter document with certain parameters, the attacker could gain rights, access private information, or impact the availability of the wiki.
Recommendations For CKEditor Integration UI versions prior to 1.64.3, upgrade to version 1.64.3 or later. For XWiki Platform versions prior to 14.6 RC1, upgrade to version 14.6 RC1 or later. As a temporary workaround, consider restricting access to the CKEditor.HTMLConverter document to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2023-05265
CVE-2023-22457
GHSA-6MJP-2RM6-9G85

Affected Products

Ckeditor Integration Ui
Xwiki Platform