XWiki Platform 7.0 < 14.4.8 / 14.5 < 14.10.4 Remote Code Execution

high Web App Scanning Plugin ID 114451

Synopsis

XWiki Platform 7.0 < 14.4.8 / 14.5 < 14.10.4 Remote Code Execution

Description

XWiki Platform versions 7.0, before 14.4.8 and versions 14.5 before 14.10.4 suffer from an improper escaping in the document 'SkinsCode.XWikiSkinsSheet'. By leveraging this vulnerability, a remote and unauthenticated attacker can achieve privilege escalation and achieve code execution on the vulnerable XWiki instance.

Solution

Upgrade XWiki to version 14.4.8, 14.10.4, or later.

See Also

https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h4vp-69r8-gvjg

https://jira.xwiki.org/browse/XWIKI-20457

Plugin Details

Severity: High

ID: 114451

Type: remote

Published: 10/21/2024

Updated: 10/21/2024

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-37462

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2023-37462

Vulnerability Information

CPE: cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/14/2023

Vulnerability Publication Date: 7/14/2023

Reference Information

CVE: CVE-2023-37462