Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors
Vulnerability Description
XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is used for checking rights. The problem has been patched in XWiki 14.10 and 14.4.7 by returning a safe script API.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权API的不正确使用
Vulnerability Title
XWiki Commons 安全漏洞
Vulnerability Description
XWiki Commons是其他几个顶级 XWiki 项目共有的技术库。 XWiki Commons 存在安全漏洞,该漏洞源于 Document script API 直接返回一个 DocumentAuthors 允许设置文档的任何作者。
CVSS Information
N/A
Vulnerability Type
N/A