Description
XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been fixed in XWiki 17.0.0, 16.4.7, and 16.10.3.
Problem types
CWE-863: Incorrect Authorization
Product status
>= 16.5.0-rc-1, < 16.10.3
>= 17.0.0-rc-1, < 17.0.0
References
github.com/...atform/security/advisories/GHSA-jp4x-w9cj-97q7
github.com/...ommit/ef978315649cf83eae396021bb33603a1a5f7e42
jira.xwiki.org/browse/XWIKI-22719