PT-2023-4820 · Xwiki+1 · Xwiki Platform+1
Manuel Leduc
·
Published
2023-06-30
·
Updated
2023-07-10
·
CVE-2023-36477
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 14.10.6
XWiki Platform versions prior to 15.1
XWiki Platform versions older than 14.6RC1 with CKEditor Integration extension prior to 1.64.9
Description
The issue allows any user with edit rights to edit all pages in the
CKEditor space, enabling harmful actions such as removing technical documents and editing the javascript configuration of CKEditor, leading to persistent XSS.Recommendations
For XWiki Platform versions prior to 14.10.6, upgrade to version 14.10.6 or later.
For XWiki Platform versions prior to 15.1, upgrade to version 15.1 or later.
For XWiki Platform versions older than 14.6RC1, update the CKEditor Integration extension to version 1.64.9 or later.
As a temporary workaround, consider restricting the
edit and delete rights to a trusted user or group, such as the XWiki.XWikiAdminGroup group, to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ckeditor
Xwiki Platform