← voltar
CVE-2023-29506mediumCWE-79

org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticated endpoints

28Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 5.4epss 1.7%
probabilidade de exploração
1.7%top 25% das CVEs
exploração observada
nãonenhuma fonte reporta
XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Produtos afetados
xwiki · xwiki-platform