CVE-2023-26056

CVSS V2 None CVSS V3 None
Description
XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWiki 14.8-rc-1, 14.4.5, and 13.10.10. There are no known workarounds for this issue.
Overview
  • CVE ID
  • CVE-2023-26056
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-02T19:15:10
  • Last Modified Date
  • 2023-03-13T16:15:29
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 3.1 13.10.10
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 14.0 14.4.5
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 14.5 14.8
cpe:2.3:a:xwiki:xwiki:3.0:milestone1:*:*:*:*:*:* 1 OR
cpe:2.3:a:xwiki:xwiki:3.0:milestone2:*:*:*:*:*:* 1 OR
cpe:2.3:a:xwiki:xwiki:3.0:milestone3:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 05:52:36 Added to TrackCVE
2023-04-17 05:52:38 Weakness Enumeration new