CVE-2023-29206
15.04.2023, 16:15
XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object and to craft a script allowing to perform some operations when executing by a user with appropriate rights. This has been patched in XWiki 14.9-rc-1 by only executing the script if the author of it has Script rights.
Vendor | Product | Version |
---|---|---|
xwiki | xwiki | 3.0 < 𝑥 ≤ 14.8 |
xwiki | xwiki | 3.0 |
xwiki | xwiki | 3.0:milestone_2 |
xwiki | xwiki | 3.0:milestone3 |
xwiki | xwiki | 3.0:rc1 |
𝑥
= Vulnerable software versions
References