XWiki Platform allows unprivileged users to make arbitrary select queries using DatabaseListProperty and suggest.vm
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.5epss 0.6%
probabilidad de explotación
0.6%top 51% de las CVE
explotación observada
noninguna fuente lo reporta
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There is no workaround for this vulnerability other than upgrading.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Productos afectados
xwiki · xwiki-platform