Back to overview

CVE-2023-26471

CRITICAL
10.0
CVSS 3.1
Description
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means that any user with comment right can use the async macro to make it execute any wiki content with the right of superadmin. This has been patched in XWiki 14.9, 14.4.6, and 13.10.10. The only known workaround consists of applying a patch and rebuilding and redeploying `org.xwiki.platform:xwiki-platform-rendering-async-macro`.

Metadata

CVE ID
CVE-2023-26471
State
PUBLISHED
Assigner
GitHub_M
Reserved
2023-02-23 23:22 UTC
Published
2023-03-02 18:28 UTC
Last updated
2025-03-05 19:54 UTC
Primary CWE
CWE-284
CWE-284: Improper Access Control
Vendor / Product
xwiki / xwiki-platform
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
xwiki xwiki-platform >= 11.6-rc-1, < 13.10.10, >= 14.0, < 14.4.6, >= 14.5, < 14.9
Weakness (CWE)
CWESourceDescription
CWE-284 cna CWE-284: Improper Access Control
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References (3)
Back to overview