CVE-2023-26474

CVSS V2 None CVSS V3 None
Description
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.
Overview
  • CVE ID
  • CVE-2023-26474
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-02T19:15:11
  • Last Modified Date
  • 2023-03-13T17:40:45
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 13.10 13.10.11
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 14.0 14.4.7
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 14.5 14.10
References
Reference URL Reference Tags
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-3738-p9x3-mv9r Exploit Vendor Advisory
https://jira.xwiki.org/browse/XWIKI-20373 Exploit Issue Tracking Patch Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 05:52:52 Added to TrackCVE
2023-04-17 05:52:55 Weakness Enumeration new