XWiki Platform allows unprivileged users to make arbitrary select queries using DatabaseListProperty and suggest.vm
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.6%
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
nono source reports it
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There is no workaround for this vulnerability other than upgrading.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
xwiki · xwiki-platform