CRITICAL 9.9 Maven
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
GHSA-3738-p9x3-mv9r · CVE-2023-26474
Published · Modified
Description
Impact
It's possible to use the right of an existing document content author to execute a text area property.
To reproduce:
- As an admin with programming rights, create a new user without script or programming right.
- Login with the freshly created user.
- Insert the following text in source mode in the about section:
{{groovy}}println("hello from groovy!"){{/groovy}}
- Click "Save & View"
Patches
This has been patched in XWiki 14.10, 14.4.7, and 13.10.11.
Workarounds
No known workaround.
References
https://jira.xwiki.org/browse/XWIKI-20373
For more information
If you have any questions or comments about this advisory:
- Open an issue in Jira
- Email us at Security ML
Ready to move
Start Securing
Free, no credit card | First findings in minutes