PT-2024-27963 · Xwiki · Xwiki Platform
Tmortagne
·
Published
2024-06-24
·
Updated
2024-06-26
·
CVE-2024-38369
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 15.0 RC1
Description
The content of a document included using
{{include reference="targetdocument"/}} is executed with the rights of the includer and not with the rights of its author. This means that any user able to modify the target document can impersonate the author of the content which used the include macro.Recommendations
For versions prior to 15.0 RC1, make sure to protect any included document to ensure only allowed users can modify it.
A workaround is available in 14.10.2 to allow forcing the execution of the included content with the target content author instead of the default behavior.
Update to XWiki 15.0 RC1 or later, where the default behavior has been made safe.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform