Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-49280— Data leak of password hash through xwiki change request

Quick assessment

Affected
xwiki-contrib application-changerequest
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Change Request是XWiki Contrib开源的一个库。 XWiki Contrib Change Request存在安全漏洞,该漏洞源于允许在 wiki 上请求更改,而无需直接发布更改。

CVSS 7.7 · High EPSS 0.94% · P60

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-49280

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Data leak of password hash through xwiki change request
Source: CVE Program / CVE List V5
Vulnerability Description
XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the changes. Change request allows to edit any page by default, and the changes are then exported in an XML file that anyone can download. So it's possible for an attacker to obtain password hash of users by performing an edit on the user profiles and then downloading the XML file that has been created. This is also true for any document that might contain password field and that a user can view. This vulnerability impacts all version of Change Request, but the impact depends on the rights that has been set on the wiki since it requires for the user to have the Change request right (allowed by default) and view rights on the page to target. This issue cannot be easily exploited in an automated way. The patch consists in denying to users the right of editing pages that contains a password field with change request. It means that already existing change request for those pages won't be removed by the patch, administrators needs to take care of it. The patch is provided in Change Request 1.10, administrators should upgrade immediately. It's possible to workaround the vulnerability by denying manually the Change request right on some spaces, such as XWiki space which will include any user profile by default.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
Source: CVE Program / CVE List V5
Vulnerability Title
XWiki Contrib Change Request 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Change Request是XWiki Contrib开源的一个库。 XWiki Contrib Change Request存在安全漏洞,该漏洞源于允许在 wiki 上请求更改,而无需直接发布更改。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
xwiki-contrib application-changerequest >= 0.1, < 1.10 -

II. Public POCs for CVE-2023-49280

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 10349 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2023-49280

请登录查看更多情报信息。

Patches & Fixes for CVE-2023-49280 (1)

Vendor Advisories for CVE-2023-49280 (1)

Other References for CVE-2023-49280 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-49280

No comments yet


Leave a comment