Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-50732


XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.


Published

2023-12-21T20:15:07.900

Last Modified

2024-11-21T08:37:14.083

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-863
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xwiki xwiki < 14.10.7 Yes
Application xwiki xwiki < 15.2 Yes

References