CVE Vulnerabilities

CVE-2023-26474

Published: Mar 02, 2023 | Modified: Mar 13, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

XWiki Platform is a generic wiki platform. Starting in version 13.10, its possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.

Affected Software

Name Vendor Start Version End Version
Xwiki Xwiki 13.10 (including) 13.10.11 (excluding)
Xwiki Xwiki 14.0 (including) 14.4.7 (excluding)
Xwiki Xwiki 14.5 (including) 14.10 (excluding)

References