Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
Vulnerability Description
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
访问控制不恰当
Vulnerability Title
XWiki Platform 访问控制错误漏洞
Vulnerability Description
XWiki Platform是法国XWiki公司的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform存在访问控制错误漏洞,该漏洞源于可有可能利用现有文档内容作者的权限来执行文本区属性。
CVSS Information
N/A
Vulnerability Type
N/A