CVE-2022-24897
- EPSS 0.27%
- Veröffentlicht 02.05.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:20
APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perfo...
CVE-2022-24819
- EPSS 4.32%
- Veröffentlicht 08.04.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:10
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in X...
CVE-2022-24820
- EPSS 0.12%
- Veröffentlicht 08.04.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:10
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patc...
CVE-2022-24821
- EPSS 0.7%
- Veröffentlicht 08.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:10
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or J...
CVE-2022-23620
- EPSS 0.31%
- Veröffentlicht 09.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:57
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions AbstractSxExportURLFactoryActionHandler#processSx does not escape anything from SSX document references when serializing it ...
CVE-2022-23621
- EPSS 0.11%
- Veröffentlicht 09.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:57
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through X...
CVE-2022-23622
- EPSS 0.5%
- Veröffentlicht 09.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:57
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is a cross site scripting (XSS) vector in the `registerinline.vm` template related to the `xredirect` hidden field. Th...
CVE-2022-23619
- EPSS 0.07%
- Veröffentlicht 09.02.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:56
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is cl...
CVE-2022-23615
- EPSS 0.05%
- Veröffentlicht 09.02.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:56
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can save a document with the right of the current user which allow accessing API requiring progra...
CVE-2022-23616
- EPSS 2.49%
- Veröffentlicht 09.02.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:56
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile an...