Skip to content

A user without programming right can save a document which will have programming right

Moderate
tmortagne published GHSA-f4cj-3q3h-884r Feb 9, 2022

Package

maven org.xwiki.platform:xwiki-platform-oldcore (Maven)

Affected versions

>= 1.0

Patched versions

13.0

Description

Impact

Any user with SCRIPT right (EDIT right before XWiki 7.4) can save a document with the right of the current user which allow accessing API requiring programming right if the current user has programming right.

Patches

It has been patched in XWiki 13.0.

Workarounds

The only workaround is to give SCRIPT right only to trusted users.

References

https://jira.xwiki.org/browse/XWIKI-5024

For more information

If you have any questions or comments about this advisory:

Severity

Moderate
6.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

CVE ID

CVE-2022-23615

Weaknesses