MEDIUM🇵🇱 Wersja polska

CVE-2022-24898

CVSS 4.9v3.1pub. 2022-04-28upd. 2024-11-21

org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service. The problem has been patched in versions 12.10.10, 13.4.4, and 13.8-rc-1. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
  • Xwiki Commons

    APP
    Xwiki
    2.7 – 12.10.10 (excl.)13.0 – 13.4.4 (excl.)13.5 – 13.8 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XXE
CWE
References

Related vulnerabilities

CVE-2023-36471CRITICAL9.0PL ✓same product

XWiki Commons: RCE i XSS przez niedostateczną sanityzację HTML (form/input)

CVE-2023-29528CRITICAL9.0PL ✓same product

XWiki Commons: XSS przez nieprawidłowe komentarze HTML prowadzący do RCE

CVE-2023-26055CRITICAL9.9PL ✓same product

XWiki Commons — wstrzyknięcie kodu przez profil użytkownika (RCE)

CVE-2025-24893CRITICAL9.8⚠ KEVPL ✓same vendor

XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch

CVE-2025-65091CRITICAL10.0PL ✓same vendor

SQL Injection w XWiki Full Calendar Macro — dostęp bez uwierzytelnienia