Xwiki

Xwiki

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.36%
  • Veröffentlicht 23.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without the right to view documents can deduce their existence by repeated Livetable queries. The issue has been patched in XWiki 14.6RC1, ...

  • EPSS 0.2%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to pat...

Exploit
  • EPSS 1.1%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properti...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users w...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disab...

  • EPSS 2.01%
  • Veröffentlicht 22.11.2022 01:15:36
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in...

  • EPSS 0.61%
  • Veröffentlicht 22.11.2022 01:15:34
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized use...

Exploit
  • EPSS 44.19%
  • Veröffentlicht 08.09.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:22

XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which ...

Exploit
  • EPSS 43.65%
  • Veröffentlicht 08.09.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:23

XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts...

Exploit
  • EPSS 21.71%
  • Veröffentlicht 08.09.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:23

XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groov...