PT-2023-4820 · Xwiki+1 · Xwiki Platform+1

Manuel Leduc

·

Published

2023-06-30

·

Updated

2023-07-10

·

CVE-2023-36477

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 14.10.6 XWiki Platform versions prior to 15.1 XWiki Platform versions older than 14.6RC1 with CKEditor Integration extension prior to 1.64.9
Description The issue allows any user with edit rights to edit all pages in the CKEditor space, enabling harmful actions such as removing technical documents and editing the javascript configuration of CKEditor, leading to persistent XSS.
Recommendations For XWiki Platform versions prior to 14.10.6, upgrade to version 14.10.6 or later. For XWiki Platform versions prior to 15.1, upgrade to version 15.1 or later. For XWiki Platform versions older than 14.6RC1, update the CKEditor Integration extension to version 1.64.9 or later. As a temporary workaround, consider restricting the edit and delete rights to a trusted user or group, such as the XWiki.XWikiAdminGroup group, to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-05283
CVE-2023-36477
GHSA-793W-G325-HRW2

Affected Products

Ckeditor
Xwiki Platform