CVE-2022-24821
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/04/2022
Last modified:
15/04/2022
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | 12.0.0 (including) | 12.10.11 (excluding) |
| cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | 13.4.0 (including) | 13.4.6 (excluding) |
| cpe:2.3:a:xwiki:xwiki:13.10:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



