CVE-2023-32069

CVSS v3.1 8.8 (High)
88% Progress
EPSS 0.21 % (59th)
0.21% Progress
Affected Products 1
Advisories 1

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This has been patched in XWiki 15.0-rc-1 and 14.10.4. There are no known workarounds.

Weaknesses
CWE-863
Incorrect Authorization
CVE Status
PUBLISHED
CNA
GitHub, Inc.
Published Date
2023-05-09 16:15:15
(16 months ago)
Updated Date
2023-05-16 17:34:32
(16 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Xwiki from 3.4 version and prior 14.10.4 version cpe:2.3:a:xwiki:xwiki >= 3.4 < 14.10.4
  Xwiki 3.3 Milestone2 cpe:2.3:a:xwiki:xwiki:3.3:milestone2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...