CVE-2023-26471
- EPSS 1.52%
- Veröffentlicht 02.03.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:34
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the re...
CVE-2023-26472
- EPSS 1.18%
- Veröffentlicht 02.03.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:34
XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even t...
CVE-2023-26473
- EPSS 0.18%
- Veröffentlicht 02.03.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:34
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There i...
CVE-2023-26474
- EPSS 0.55%
- Veröffentlicht 02.03.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:35
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no know...
CVE-2023-26475
- EPSS 24.52%
- Veröffentlicht 02.03.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:35
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating t...
CVE-2023-26476
- EPSS 0.37%
- Veröffentlicht 02.03.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:35
XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveTableResults` and `WikisLiveTableResultsMacros`. The issue can be fixed by upgrading to versions 14.7-...
CVE-2023-26056
- EPSS 0.34%
- Veröffentlicht 02.03.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:50:40
XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWiki 14.8-rc-...
CVE-2023-26479
- EPSS 0.29%
- Veröffentlicht 02.03.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:35
XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well by the parser. As a consequence, some pages becomes unusable, including the user index (if the page co...
CVE-2023-26480
- EPSS 3.68%
- Veröffentlicht 02.03.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:36
XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known...
CVE-2023-26477
- EPSS 41.74%
- Veröffentlicht 02.03.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:51:35
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combina...