Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-23616— Remote code execution in xwiki-platform

Quick assessment

Affected
xwiki xwiki-platform
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Xwiki Platform是法国Xwiki公司的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform存在注入漏洞,该漏洞源于影响版本中它的非特权用户可以执行远程代码执行注射一个groovy脚本在自己的配置文件,通过调用重置密码功能特性是执行以来节省用户配置文件的编程XWiki影响版本的权利。该问题已在XWiki 13.1RC1中修复。

CVSS 8.8 · High EPSS 2.10% · P81

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-23616

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Remote code execution in xwiki-platform
Source: CVE Program / CVE List V5
Vulnerability Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset password feature since the feature is performing a save of the user profile with programming rights in the impacted versions of XWiki. The issue has been patched in XWiki 13.1RC1. There are two different possible workarounds, each consisting of modifying the XWiki/ResetPassword page. 1. The Reset password feature can be entirely disabled by deleting the XWiki/ResetPassword page. 2. The script in XWiki/ResetPassword can also be modified or removed: an administrator can replace it with a simple email contact to ask an administrator to reset the password.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Source: CVE Program / CVE List V5
Vulnerability Title
Xwiki Platform 注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Xwiki Platform是法国Xwiki公司的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform存在注入漏洞,该漏洞源于影响版本中它的非特权用户可以执行远程代码执行注射一个groovy脚本在自己的配置文件,通过调用重置密码功能特性是执行以来节省用户配置文件的编程XWiki影响版本的权利。该问题已在XWiki 13.1RC1中修复。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
xwiki xwiki-platform > 3.1M1, < 13.1RC1 -

II. Public POCs for CVE-2022-23616

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-23616

登录查看更多情报信息。

Vendor Advisories for CVE-2022-23616 (1)

Other References for CVE-2022-23616 (1)

Same Patch Batch · xwiki · 2022-02-09 · 8 CVEs total

CVE-2022-23622 7.4 HIGH Cross site scripting in registration template in xwiki-platform
CVE-2022-23620 6.8 MEDIUM Path traversal in xwiki-platform-skin-skinx
CVE-2022-23617 6.5 MEDIUM Missing authorization in xwiki-platform
CVE-2022-23621 5.5 MEDIUM Missing authorization in xwiki-platform
CVE-2022-23615 5.4 MEDIUM Partial authorization bypass on document save in xwiki-platform
CVE-2022-23619 5.3 MEDIUM Information exposure in xwiki-platform
CVE-2022-23618 4.7 MEDIUM Open Redirect in xwiki-platform

IV. Related Vulnerabilities

V. Comments for CVE-2022-23616

No comments yet


Leave a comment