Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2023-45136 โ€” AI Deep Analysis Summary

CVSS 9.7 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: Reflected XSS in XWiki Platform. ๐Ÿ“‰ **Consequences**: Attackers inject malicious scripts via document name validation. Victims executing the link suffer arbitrary action execution under their own rights.

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: CWE-79 (Cross-site Scripting). ๐Ÿ’ฅ **Flaw**: Improper neutralization of user input during document name validation when specific name strategies are enabled.

Q3Who is affected? (Versions/Components)

๐Ÿ“ฆ **Affected**: XWiki Platform. ๐Ÿ“… **Versions**: 12.0-rc-1 through 12.10.11 AND 15.0 through 15.5-rc-1. ๐Ÿข **Vendor**: XWiki Foundation.

Q4What can hackers do? (Privileges/Data)

๐Ÿ’ฃ **Hackers Can**: Execute arbitrary JavaScript actions. ๐ŸŽญ **Privileges**: Act with the **victim user's rights**. ๐Ÿ“‚ **Data**: Potential access to sensitive wiki content or configuration based on user permissions.

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Threshold**: Medium. ๐Ÿ”‘ **Auth**: No authentication required for the vulnerability itself. ๐Ÿ–ฑ๏ธ **Config**: Requires User Interaction (UI:R) to click a malicious link.โ€ฆ

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ” **Public Exp?**: Yes. ๐Ÿ“œ **PoC**: Available via Nuclei templates (ProjectDiscovery). ๐ŸŒ **Link**: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-45136.yaml

Q7How to self-check? (Features/Scanning)

๐Ÿ”Ž **Self-Check**: Scan for XWiki instances. ๐Ÿงช **Feature**: Check if 'Name Strategy' validation is enabled. ๐Ÿ› ๏ธ **Tool**: Use Nuclei with the specific CVE template to detect the reflection point.

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fixed**: Yes. ๐Ÿฉน **Patch**: Update to **12.10.12+** or **15.5-rc-1+**. ๐Ÿ”— **Commit**: ba56fda175156dd35035f2b8c86cbd8ef1f90c2e. ๐Ÿ“ข **Advisory**: GHSA-qcj9-gcpg-4w2w.

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch?**: Disable the specific **Name Strategy** for document name validation. ๐Ÿ›‘ **Mitigation**: Ensure the feature is turned off if not strictly needed. This prevents the input vector from being triggered.

Q10Is it urgent? (Priority Suggestion)

โšก **Urgency**: High Priority. ๐Ÿšจ **Reason**: CVSS Score is High (C:H, I:H, A:H). ๐Ÿ“‰ **Impact**: Full compromise of user context. ๐Ÿƒ **Action**: Patch immediately or disable the vulnerable configuration.