Xwiki Ckeditor Integration vulnerabilities
2 known vulnerabilities affecting xwiki/ckeditor_integration.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-22457P2HIGHCVSS 8.8fixed in 1.64.32023-01-04
CVE-2023-22457 [HIGH] CWE-352 CVE-2023-22457: CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3
CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the rights of the current user. If a privileged user with programming rights was tricked into executing a GET request
nvd
CVE-2023-36477P4MEDIUMCVSS 5.4≥ 1.9, < 1.64.92023-06-30
CVE-2023-36477 [MEDIUM] CWE-79 CVE-2023-36477: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as removing technical documents, leading to loss of service and editing the javascript configuration of CKEd
nvd