XWiki Platform是XWiki基金会的一套用于创建Web协作应用程序的Wiki平台。 XWiki 存在安全漏洞,该漏洞源于 XWiki 中基于 Solr 的搜索会向任何有权查看相应用户配置文件的人公开所有用户的密码哈希值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 7.2-milestone-2, < 14.10.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren't accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-50719.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-50721 | 10.0 CRITICAL | XWiki Platform RCE from account through SearchAdmin |
| CVE-2023-50723 | 10.0 CRITICAL | XWiki Platform remote code execution/programming rights with configuration section from an |
| CVE-2023-50722 | 9.7 CRITICAL | XWiki Platform XSS/CSRF Remote Code Execution in XWiki.ConfigurableClass |
| CVE-2023-50720 | 5.3 MEDIUM | XWiki Platform Solr search discloses email addresses of users |
No comments yet