Xwiki

Xwiki

244 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.41%
  • Veröffentlicht 02.03.2023 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 14.3-rc-1, `org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAttachment` returns an instance of `com.xpn.xwiki.doc.XWikiAttachment`. This class is not supported to ...

  • EPSS 0.19%
  • Veröffentlicht 23.11.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:05

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form. This may...

  • EPSS 0.09%
  • Veröffentlicht 23.11.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` feature of XWiki was used, the password was then stored in plain text in database. This only concerns XWiki...

Exploit
  • EPSS 18.93%
  • Veröffentlicht 23.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:05

xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrary Groovy, P...

Exploit
  • EPSS 23.62%
  • Veröffentlicht 23.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly accessible documents including the menu macro can execute arbitrary Groovy, Python or Velocity code in XWik...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 23.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without the right to view documents can deduce their existence by repeated Livetable queries. The issue has been patched in XWiki 14.6RC1, ...

  • EPSS 0.82%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to pat...

Exploit
  • EPSS 5.94%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properti...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users w...

Exploit
  • EPSS 0.93%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disab...