Description
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional parameters. This has been patched in the supported versions 13.10.10, 14.9-rc-1, and 14.4.6. As a workaround, it is possible to edit `FlamingoThemesCode.WebHomeSheet` and manually perform the changes from the patch fixing the issue.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- xwiki / xwiki-platform>= 6.2.4, < 13.10.10 – >= 6.2.4, < 13.10.10
- xwiki / xwiki-platform>= 14.0, < 14.4.6 – >= 14.0, < 14.4.6
- xwiki / xwiki-platform>= 14.5, < 14.9-rc-1 – >= 14.5, < 14.9-rc-1
References
- VENDOR_ADVISORYhttps://github.com/xwiki/xwiki-platform/security/advisories/GHSA-x2qm-r4wx-8gpg
- PATCHhttps://github.com/xwiki/xwiki-platform/commit/ea2e615f50a918802fd60b09ec87aa04bc6ea8e2#diff-e2153fa59f9d92ef67b0afbf27984bd17170921a3b558fac227160003d0dfd2aR283-R284
- MISChttps://jira.xwiki.org/browse/XWIKI-19757