CVE-2023-50732
21.12.2023, 20:15
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.Enginsight
Vendor | Product | Version |
---|---|---|
xwiki | xwiki | 8.3 ≤ 𝑥 < 14.10.7 |
xwiki | xwiki | 15.0 ≤ 𝑥 < 15.2 |
𝑥
= Vulnerable software versions
References