Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-40572


XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/programming right, thus compromising the confidentiality, integrity and availability of the whole XWiki installation. When a user with script right views this image and a log message `ERROR foo - Script executed!` appears in the log, the XWiki installation is vulnerable. This has been patched in XWiki 14.10.9 and 15.4RC1 by requiring a CSRF token for the actual page creation.


Published

2023-08-24T02:15:09.643

Last Modified

2024-11-21T08:19:44.413

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xwiki xwiki < 14.10.9 Yes
Application xwiki xwiki 15.0 Yes
Application xwiki xwiki 15.0 Yes
Application xwiki xwiki 15.1 Yes
Application xwiki xwiki 15.1 Yes
Application xwiki xwiki 15.2 Yes
Application xwiki xwiki 15.2 Yes
Application xwiki xwiki 15.3 Yes
Application xwiki xwiki 15.3 Yes

References