Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-37910— org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move

CVSS 8.1 · High EPSS 0.57% · P69
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-37910

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move
Source: NVD (National Vulnerability Database)
Vulnerability Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with the introduction of attachment move support in version 14.0-rc-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, an attacker with edit access on any document (can be the user profile which is editable by default) can move any attachment of any other document to this attacker-controlled document. This allows the attacker to access and possibly publish any attachment of which the name is known, regardless if the attacker has view or edit rights on the source document of this attachment. Further, the attachment is deleted from the source document. This vulnerability has been patched in XWiki 14.4.8, 14.10.4, and 15.0 RC1. There is no workaround apart from upgrading to a fixed version.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制缺失
Source: NVD (National Vulnerability Database)
Vulnerability Title
XWiki Platform 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
XWiki Platform是法国XWiki基金会的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 存在安全漏洞,该漏洞源于对任何文档具有编辑权限的攻击者可以将任何其他文档的任何附件移动到此攻击者控制的文档。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
xwikixwiki-platform >= 14.0-rc-1, < 14.4.8 -

II. Public POCs for CVE-2023-37910

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-37910

登录查看更多情报信息。

Same Patch Batch · xwiki · 2023-10-25 · 10 CVEs total

CVE-2023-3791310.0 CRITICALorg.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file
CVE-2023-3791210.0 CRITICALXWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro
CVE-2023-3790910.0 CRITICALPrivilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheet
CVE-2023-451369.7 CRITICALXWiki Platform web templates vulnerable to reflected XSS in the create document form if na
CVE-2023-451379.1 CRITICALXWiki Platform XSS with edit right in the create document form for existing pages
CVE-2023-451359.1 CRITICALXWiki users can be tricked to execute scripts as the create page action doesn't display th
CVE-2023-451349.1 CRITICALXWiki Platform XSS vulnerability from account in the create page form via template provide
CVE-2023-379089.1 CRITICALorg.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in I
CVE-2023-379116.5 MEDIUMorg.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created doc

IV. Related Vulnerabilities

V. Comments for CVE-2023-37910

No comments yet


Leave a comment