Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
XWIKI 错误处理数据泄露漏洞
Vulnerability Description
XWiki 1.0 B1和1.0 B2中的"你不被允许..."错误处理把doc变量与全部文件内容和无视用户观察权的元数据相联系,使远程验证用户可以借助一个用户个性皮肤打印出doc变量的内容属性来读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A