Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 6.2-milestone-1, < 14.10.5 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication page to perform a XSS, e.g. by using URL such as: > xwiki/bin/view/AppWithinMinutes/DeleteApplication?appName=Menu&resolve=true&xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 6.2-milestone-1. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35161.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-34465 | 10.0 CRITICAL | XWiki Platform's Mail.MailConfig can be edited by any user with edit rights |
| CVE-2023-35152 | 10.0 CRITICAL | XWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTable |
| CVE-2023-35150 | 9.9 CRITICAL | XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation appl |
| CVE-2023-35156 | 9.7 CRITICAL | XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in del |
| CVE-2023-35158 | 9.7 CRITICAL | XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in res |
| CVE-2023-35159 | 9.7 CRITICAL | XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in del |
| CVE-2023-35160 | 9.7 CRITICAL | XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue paramet |
| CVE-2023-35162 | 9.7 CRITICAL | XPlatform Wiki vulnerable to cross-site scripting via xcontinue parameter in preview actio |
| CVE-2023-34464 | 9.1 CRITICAL | XWiki vulnerable to stored cross-site scripting via any wiki document and the displayconte |
| CVE-2023-35153 | 9.1 CRITICAL | XWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name p |
| CVE-2023-35155 | 8.8 HIGH | XWiki Platform vulnerable to cross-site scripting in target parameter via share page by em |
| CVE-2023-35157 | 8.5 HIGH | XWiki Platform vulnerable to reflected cross-site scripting via delattachment action |
| CVE-2023-34467 | 7.5 HIGH | XWiki Platform may retrieve email addresses of all users |
| CVE-2023-35151 | 7.5 HIGH | XWiki Platform may show email addresses in clear in REST results |
| CVE-2023-34466 | 4.3 MEDIUM | XWiki Platform's tags on non-viewable pages can be revealed to users |
No comments yet