XWiki Platform是XWiki基金会的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 存在安全漏洞,该漏洞源于搜索管理界面无法正确转义搜索用户界面扩展的 id 和标签,从而允许注入 XWiki 包含脚本宏(包括允许远程代码执行的 Groovy 宏)的语法,影响整个 XWiki 实例的机密性、完整性和可用性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 4.5-rc-1, < 14.10.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-50723 | 10.0 CRITICAL | XWiki Platform remote code execution/programming rights with configuration section from an |
| CVE-2023-50722 | 9.7 CRITICAL | XWiki Platform XSS/CSRF Remote Code Execution in XWiki.ConfigurableClass |
| CVE-2023-50719 | 7.5 HIGH | XWiki Platform Solr search discloses password hashes of all users |
| CVE-2023-50720 | 5.3 MEDIUM | XWiki Platform Solr search discloses email addresses of users |
No comments yet