XWiki Platform vulnerable to privilege escalation (PR) from account through TipsPanel
Package
Affected versions
>= 8.1-milestone-1, < 14.10.5
>= 15.0-rc-1, < 15.1-rc-1
Patched versions
14.10.5
15.1-rc-1
Description
Published to the GitHub Advisory Database
Jun 20, 2023
Reviewed
Jun 20, 2023
Published by the National Vulnerability Database
Jun 20, 2023
Last updated
Nov 10, 2023
Impact
It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension.
To reproduce:
The groovy macro is executed, after the fix you get an error instead.
Patches
This has been patched in XWiki 15.1-rc-1 and 14.10.5.
Workarounds
There are no known workarounds for it.
References
For more information
If you have any questions or comments about this advisory:
References