XWiki Platform是法国XWiki公司的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 存在注入漏洞,该漏洞源于没有脚本或编程权限的用户可以使用 wiki 编辑器编辑用户配置文件(或任何其他文档)并添加 groovy 脚本内容。保存后查看文档将在提供代码执行的服务器上下文中执行 groovy 脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 7.4.4, < 14.10.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-29514 | 10.0 CRITICAL | Code injection in template provider administration in xwiki-platform |
| CVE-2023-29510 | 10.0 CRITICAL | Code injection via unescaped translations in xwiki-platform |
| CVE-2023-29523 | 10.0 CRITICAL | Code injection in display method used in user profiles in xwiki-platform |
| CVE-2023-29524 | 10.0 CRITICAL | Code injection from account through XWiki.SchedulerJobSheet in xwiki-platform |
| CVE-2023-29525 | 10.0 CRITICAL | Privilege escalation from view right on XWiki.Notifications.Code.LegacyNotificationAdminis |
| CVE-2023-29526 | 10.0 CRITICAL | Async and display macro allow displaying and interacting with any document in restricted m |
| CVE-2023-29516 | 9.9 CRITICAL | Code injection from view right on XWiki.AttachmentSelector in xwiki-platform |
| CVE-2023-29512 | 9.9 CRITICAL | Code injection in xwiki-platform-web-templates |
| CVE-2023-29522 | 9.9 CRITICAL | Code injection from view right on XWiki.ClassSheet in xwiki-platform |
| CVE-2023-29518 | 9.9 CRITICAL | Code injection from view right using Invitation.InvitationCommon in xwiki-platform |
| CVE-2023-29519 | 9.1 CRITICAL | Code injection in org.xwiki.platform:xwiki-platform-attachment-ui |
| CVE-2023-29521 | 8.4 HIGH | Code injection from account/view through VFS Tree macro in xwiki-platform |
| CVE-2023-29515 | 7.7 HIGH | Cross-site scripting (XSS) in xwiki-platform |
| CVE-2023-29517 | 7.5 HIGH | Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-pla |
| CVE-2023-29513 | 5.0 MEDIUM | Users can be created even when registration is disabled without validation via the templat |
| CVE-2023-29520 | 4.3 MEDIUM | Page render failure due to broken translations in xwiki-platform |
No comments yet