Xwiki Platform是法国Xwiki公司的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform存在注入漏洞,该漏洞源于影响版本中它的非特权用户可以执行远程代码执行注射一个groovy脚本在自己的配置文件,通过调用重置密码功能特性是执行以来节省用户配置文件的编程XWiki影响版本的权利。该问题已在XWiki 13.1RC1中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | > 3.1M1, < 13.1RC1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-23622 | 7.4 HIGH | Cross site scripting in registration template in xwiki-platform |
| CVE-2022-23620 | 6.8 MEDIUM | Path traversal in xwiki-platform-skin-skinx |
| CVE-2022-23617 | 6.5 MEDIUM | Missing authorization in xwiki-platform |
| CVE-2022-23621 | 5.5 MEDIUM | Missing authorization in xwiki-platform |
| CVE-2022-23615 | 5.4 MEDIUM | Partial authorization bypass on document save in xwiki-platform |
| CVE-2022-23619 | 5.3 MEDIUM | Information exposure in xwiki-platform |
| CVE-2022-23618 | 4.7 MEDIUM | Open Redirect in xwiki-platform |
No comments yet