CVE-2023-36468
- EPSS 7.19%
- Veröffentlicht 29.06.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki installation is upgraded and that upgrade contains a fix for a bug in a document, just a new version of that document is added. In ...
CVE-2023-36469
- EPSS 47.07%
- Veröffentlicht 29.06.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros tha...
CVE-2023-36470
- EPSS 14.17%
- Veröffentlicht 29.06.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an existing document with an icon set, an attacker can inject XWiki syntax and Velocity code that is executed...
CVE-2023-35155
- EPSS 47.03%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter`...
CVE-2023-35156
- EPSS 9.28%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the delete template to pe...
CVE-2023-35157
- EPSS 1.13%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to perform an XSS by forging a request to a delete attachment action with a specific attachment name. Now this XSS can be exploited...
CVE-2023-35158
- EPSS 7.64%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the restore template to p...
CVE-2023-35159
- EPSS 3.38%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespace template ...
CVE-2023-35160
- EPSS 3.38%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit template to ...
CVE-2023-35161
- EPSS 3.38%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication pag...