CVE-2022-41927
- EPSS 0.28%
- Veröffentlicht 23.11.2022 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:24:05
XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to pat...
CVE-2022-41928
- EPSS 0.98%
- Veröffentlicht 23.11.2022 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:24:05
XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properti...
CVE-2022-41929
- EPSS 0.71%
- Veröffentlicht 23.11.2022 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:24:05
org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users w...
CVE-2022-41930
- EPSS 0.82%
- Veröffentlicht 23.11.2022 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:24:05
org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disab...
CVE-2022-41937
- EPSS 0.73%
- Veröffentlicht 22.11.2022 01:15:36
- Zuletzt bearbeitet 21.11.2024 07:24:06
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in...
CVE-2022-41936
- EPSS 0.72%
- Veröffentlicht 22.11.2022 01:15:34
- Zuletzt bearbeitet 21.11.2024 07:24:06
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized use...
CVE-2022-36097
- EPSS 57.39%
- Veröffentlicht 08.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:22
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which ...
- EPSS 71.04%
- Veröffentlicht 08.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:23
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts...
CVE-2022-36099
- EPSS 75.89%
- Veröffentlicht 08.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:23
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groov...
CVE-2022-36100
- EPSS 73.61%
- Veröffentlicht 08.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:23
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document ...