XWiki Platform是法国XWiki基金会的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 9.6-rc-1到 14.10.6版本、 15.0-rc-1到 15.2-rc-1版本存在注入漏洞,该漏洞源于任何可以编辑自己的用户配置文件和通知设置的用户都可以执行任意脚本宏,包括 Groovy 和 Python 宏,这些宏允许远程执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 9.6-rc-1, < 14.10.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-36468 | 10.0 CRITICAL | Upgrading doesn't prevent exploiting vulnerable XWiki documents |
| CVE-2023-36470 | 10.0 CRITICAL | Code injection in icon themes of XWiki Platform |
| CVE-2023-36471 | 9.1 CRITICAL | HTML sanitizer allows form elements in restricted in org.xwiki.commons:xwiki-commons-xml |
No comments yet