CVE-2022-23616
published 2022-02-09CVE-2022-23616: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.02%
78.5th percentile
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset password feature since the feature is performing a save of the user profile with programming rights in the impacted versions of XWiki. The issue has been patched in XWiki 13.1RC1. There are two different possible workarounds, each consisting of modifying the XWiki/ResetPassword page. 1. The Reset password feature can be entirely disabled by deleting the XWiki/ResetPassword page. 2. The script in XWiki/ResetPassword can also be modified or removed: an administrator can replace it with a simple email contact to ask an administrator to reset the password.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xwiki | xwiki | — | — |
| xwiki | xwiki | 3.1.1 – 13.1 | — |
| xwiki | xwiki-platform | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Remote code execution in xwiki-platform
osv·2022-02-09
CVE-2022-23616 [HIGH] Remote code execution in xwiki-platform
Remote code execution in xwiki-platform
### Impact
It's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset password feature since the feature is performing a save of the user profile with programming rights in the impacted versions of XWiki.
### Patches
The problem has been patched in XWiki 13.1RC1 with a complete refactoring of the Reset password feature.
### Workarounds
There's different possible workarounds, all consisting in modifying the XWiki/ResetPassword page.
- the Reset password feature can be entirely disabled by deleting the XWiki/ResetPassword page
- the script in XWiki/ResetPassword can also be modified or removed: an administrator can replace it with a simple email contact to ask an
GHSA
Remote code execution in xwiki-platform
ghsa·2022-02-09
CVE-2022-23616 [HIGH] CWE-74 Remote code execution in xwiki-platform
Remote code execution in xwiki-platform
### Impact
It's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset password feature since the feature is performing a save of the user profile with programming rights in the impacted versions of XWiki.
### Patches
The problem has been patched in XWiki 13.1RC1 with a complete refactoring of the Reset password feature.
### Workarounds
There's different possible workarounds, all consisting in modifying the XWiki/ResetPassword page.
- the Reset password feature can be entirely disabled by deleting the XWiki/ResetPassword page
- the script in XWiki/ResetPassword can also be modified or removed: an administrator can replace it with a simple email contact to ask an
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published