CVE-2023-35157
- EPSS 1.24%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to perform an XSS by forging a request to a delete attachment action with a specific attachment name. Now this XSS can be exploited...
CVE-2023-35158
- EPSS 11.22%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the restore template to p...
CVE-2023-35159
- EPSS 5.1%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespace template ...
CVE-2023-35160
- EPSS 12.08%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit template to ...
CVE-2023-35161
- EPSS 12.08%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication pag...
CVE-2023-35162
- EPSS 12.08%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:04
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the previewactions templa...
CVE-2023-35153
- EPSS 2.09%
- Veröffentlicht 23.06.2023 18:15:13
- Zuletzt bearbeitet 21.11.2024 08:08:02
XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exploited by users with edit rights by adding a `AppWithinMinutes.FormFieldCatego...
CVE-2023-34467
- EPSS 1.19%
- Veröffentlicht 23.06.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:19
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obf...
- EPSS 33.48%
- Veröffentlicht 23.06.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with prog...
CVE-2023-35151
- EPSS 0.21%
- Veröffentlicht 23.06.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:02
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The iss...