目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-45135— XWiki Platform 安全漏洞

一分钟漏洞结论

影响对象
xwiki xwiki-platform
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

XWiki Platform是法国XWiki基金会的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 存在安全漏洞,该漏洞源于可以将标题传递给最初不显示但在第二步中执行的页面创建操作。

CVSS 9.1 · Critical EPSS 1.74% · P77
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2023-45135 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
XWiki users can be tricked to execute scripts as the create page action doesn't display the page's title
来源: CVE Program / CVE List V5
Vulnerability Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In `org.xwiki.platform:xwiki-platform-web` versions 7.2-milestone-2 until 14.10.12 and `org.xwiki.platform:xwiki-platform-web-templates` prior to versions 14.10.12 and 15.5-rc-1, it is possible to pass a title to the page creation action that isn't displayed at first but then executed in the second step. This can be used by an attacker to trick a victim to execute code, allowing script execution if the victim has script right or remote code execution including full access to the XWiki instance if the victim has programming right. For the attack to work, the attacker needs to convince the victim to visit a link like `<xwiki-host>/xwiki/bin/create/NonExistingSpace/WebHome?title=$services.logging.getLogger(%22foo%22).error(%22Script%20executed!%22)` where `<xwiki-host>` is the URL of the Wiki installation and to then click on the "Create" button on that page. The page looks like a regular XWiki page that the victim would also see when clicking the button to create a page that doesn't exist yet, the malicious code is not displayed anywhere on that page. After clicking the "Create" button, the malicious title would be displayed but at this point, the code has already been executed and the attacker could use this code also to hide the attack, e.g., by redirecting the victim again to the same page with an innocent title. It thus seems plausible that this attack could work if the attacker can place a fake "create page" button on a page which is possible with edit right. This has been patched in `org.xwiki.platform:xwiki-platform-web` version 14.10.12 and `org.xwiki.platform:xwiki-platform-web-templates` versions 14.10.12 and 15.5-rc-1 by displaying the title already in the first step such that the victim can notice the attack before continuing. It is possible to manually patch the modified files from the patch in an existing installation. For the JavaScript change, the minified JavaScript file would need to be obtained from a build of XWiki and replaced accordingly.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
对输出编码和转义不恰当
来源: CVE Program / CVE List V5
Vulnerability Title
XWiki Platform 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
XWiki Platform是法国XWiki基金会的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 存在安全漏洞,该漏洞源于可以将标题传递给最初不显示但在第二步中执行的页面创建操作。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
xwiki xwiki-platform >= 7.2-milestone-2, < 14.10.12 -

二、漏洞 CVE-2023-45135 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-45135 的情报信息

请登录查看更多情报信息。

CVE-2023-45135 补丁与修复 (1)

CVE-2023-45135 厂商安全公告 (1)

CVE-2023-45135 其他参考 (1)

同批安全公告 · xwiki · 2023-10-25 · 共 10 条

CVE-2023-37913 10.0 CRITICAL XWiki Platform 路径遍历漏洞
CVE-2023-37912 10.0 CRITICAL XWiki Rendering 安全漏洞
CVE-2023-37909 10.0 CRITICAL XWiki Platform 代码注入漏洞
CVE-2023-45136 9.7 CRITICAL XWiki Platform 跨站脚本漏洞
CVE-2023-45137 9.1 CRITICAL XWiki Platform 安全漏洞
CVE-2023-45134 9.1 CRITICAL XWiki Platform 跨站脚本漏洞
CVE-2023-37908 9.1 CRITICAL XWiki Rendering 跨站脚本漏洞
CVE-2023-37910 8.1 HIGH XWiki Platform 安全漏洞
CVE-2023-37911 6.5 MEDIUM XWiki Platform 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-45135

暂无评论


发表评论