XWiki Platform是法国XWiki公司的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform Web Templates 13.10.5之前版本和14.3RC1之前版本存在安全漏洞,该漏洞源于通过将分发向导的模板传递给xpart模板,即使禁用了用户注册,也可以创建用户帐户,这绕过了任何电子邮件验证,这可以在私有wiki上被利用,从而可能使攻击者访问wiki,根据用户配置的默认权限,这也可能使攻击者拥有对其他只读公共wiki的写入权限,也可以在配置了LDAP等外部身份验证系
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 8.0-rc-1, < 13.10.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-36100 | 9.9 CRITICAL | XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection |
| CVE-2022-36099 | 9.9 CRITICAL | XWiki Platform Wiki UI Main Wiki Eval Injection vulnerability |
| CVE-2022-36098 | 8.9 HIGH | XWiki Platform Mentions UI vulnerable to Cross-site Scripting |
| CVE-2022-36097 | 8.9 HIGH | XWiki Platform Attachment UI vulnerable to cross-site scripting in the move attachment for |
| CVE-2022-36096 | 8.9 HIGH | XWiki Platform vulnerable to Cross-site Scripting in the deleted attachments list |
| CVE-2022-36094 | 8.9 HIGH | XWiki Platform Web Parent POM vulnerable to XSS in the attachment history |
| CVE-2022-36090 | 8.1 HIGH | org.xwiki.platform:xwiki-platform-oldcore Improper Authorization check for inactive users |
| CVE-2022-36092 | 7.5 HIGH | XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login Action |
| CVE-2022-36091 | 7.5 HIGH | XWiki Platform Web Templates vulnerable to Missing Authorization and Exposure of Private P |
| CVE-2022-36095 | 4.3 MEDIUM | XWiki Cross-Site Request Forgery (CSRF) for actions on tags |
No comments yet