CVE-2022-23617
- EPSS 0.07%
- Veröffentlicht 09.02.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:56
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a new page. Th...
CVE-2022-23618
- EPSS 0.28%
- Veröffentlicht 09.02.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:56
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection against URL redirection to untrusted sites, in particular some well known parameters (xredirect) can ...
CVE-2021-32732
- EPSS 0.07%
- Veröffentlicht 04.02.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 06:07:37
### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which username(s) is actually tied to that email by forging a request to the Forgot username page. Note that since this page does not have a C...
CVE-2021-43841
- EPSS 0.46%
- Veröffentlicht 04.02.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 06:29:54
XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when executing the download action on ...
CVE-2021-32731
- EPSS 0.09%
- Veröffentlicht 01.07.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:37
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The ...
CVE-2021-32730
- EPSS 0.17%
- Veröffentlicht 01.07.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:37
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL...
CVE-2021-32729
- EPSS 0.05%
- Veröffentlicht 01.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:36
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability exists in versions prior to 12.6.88, 12.10.4, and 13.0. The script service method used to reset the authentication failures recor...
CVE-2021-32620
- EPSS 0.31%
- Veröffentlicht 28.05.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 12.10.2, a user disabled on a wiki using email verification for registration canouldre-activate themse...
CVE-2021-32621
- EPSS 0.69%
- Veröffentlicht 28.05.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 12.6.7 and 12.10.3, a user without Script or Programming right is able to execute script requiring privileges by editing gad...
CVE-2021-29459
- EPSS 0.42%
- Veröffentlicht 20.04.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:01:08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible to persistently inject scripts in XWiki versions prior to 12.6.3 and 12.8. Unregistred users can fill simple text fields. Register...