CVE-2024-21648
- EPSS 0.34%
- Veröffentlicht 09.01.2024 00:15:44
- Zuletzt bearbeitet 21.11.2024 08:54:47
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, a user can rollback to a previous version of the page to gain rights they don't have anymore. ...
CVE-2024-21651
- EPSS 0.5%
- Veröffentlicht 09.01.2024 00:15:44
- Zuletzt bearbeitet 21.11.2024 08:54:48
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, ...
CVE-2024-21650
- EPSS 93.34%
- Veröffentlicht 08.01.2024 16:15:46
- Zuletzt bearbeitet 21.11.2024 08:54:48
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbit...
CVE-2023-50732
- EPSS 1.36%
- Veröffentlicht 21.12.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 08:37:14
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.
CVE-2023-50723
- EPSS 5.39%
- Veröffentlicht 15.12.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping...
CVE-2023-50719
- EPSS 51.13%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user p...
CVE-2023-50720
- EPSS 49.72%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability,...
CVE-2023-50721
- EPSS 43.25%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the inje...
CVE-2023-50722
- EPSS 3.26%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sections. The ...
CVE-2023-48293
- EPSS 0.76%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:31:25
The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-site request forgery vulnerability in the query on XWiki tool allows executing arbitrary database queries on the database of the XWi...