CVE-2023-26055
Published on: Not Yet Published
Last Modified on: 03/13/2023 03:59:00 PM UTC
Certain versions of Commons from Xwiki contain the following vulnerability:
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in all other places where short text properties are displayed, e.g., in apps created using Apps Within Minutes that use a short text field. The problem has been patched on versions 13.10.9, 14.4.4, 14.7RC1.
- CVE-2023-26055 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
xwiki - xwiki-commons version = >= 3.1-milestone-1, < 13.10.9
- Affected Vendor/Software:
xwiki - xwiki-commons version = >= 14.0-rc-1, < 14.4.4
- Affected Vendor/Software:
xwiki - xwiki-commons version = >= 14.5, < 14.7-rc-1
CVSS3 Score: 9.9 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Privilege escalation to programming rights via user's first name · Advisory · xwiki/xwiki-commons · GitHub | github.com text/html |
![]() |
Loading... | jira.xwiki.org text/html |
![]() |
Loading... | jira.xwiki.org text/html |
![]() |
Loading... | jira.xwiki.org text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Xwiki | Commons | All | All | All | All |
Application | Xwiki | Commons | 14.4 | rc1 | All | All |
Application | Xwiki | Commons | 3.1 | milestone1 | All | All |
Application | Xwiki | Commons | 3.1 | milestone2 | All | All |
Application | Xwiki | Commons | 3.1.1 | All | All | All |
- cpe:2.3:a:xwiki:commons:*:*:*:*:*:*:*:*:
- cpe:2.3:a:xwiki:commons:14.4:rc1:*:*:*:*:*:*:
- cpe:2.3:a:xwiki:commons:3.1:milestone1:*:*:*:*:*:*:
- cpe:2.3:a:xwiki:commons:3.1:milestone2:*:*:*:*:*:*:
- cpe:2.3:a:xwiki:commons:3.1.1:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-26055 : XWiki Commons are technical libraries common to several other top level XWiki projects. Starting i… twitter.com/i/web/status/1… | 2023-03-02 19:05:38 |
![]() |
CVE-2023-26055 | 2023-03-02 19:38:31 |