XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.
The sort parameter passed to the getdeleteddocuments.vm template is inserted directly without validation or sanitization as a value of the ORDER BY clause in an SQL query. An attacker can send a crafted HTTP request with an appropriately modified sort parameter value, thereby injecting arbitrary SQL code. The attack requires no authentication or user interaction.
An attacker can read, modify, or delete data stored in the XWiki database, including potentially gaining access to sensitive information such as user data, session tokens, or wiki content.
Update XWiki Platform to version 16.10.6 or 17.3.0-rc-1 (and newer), in which the vulnerability has been fixed. Patches are available in the project repository on GitHub (commits dfd0744e9c18d24ac66a0d261dc6cafd1c209101 and f502b5d5fd36284a50890ad26d168b7d8dc80bd3).
XWiki Platform in versions from 9.4-rc-1 to 16.10.5 and from 17.0.0-rc-1 to 17.2.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XXwiki
APPXwiki9.4 – 16.10.6 (excl.)17.0.0 – 17.2.2
Related vulnerabilities
XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch
XWiki Platform — path traversal umożliwia odczyt plików konfiguracyjnych
XWiki Platform: ujawnienie plików konfiguracyjnych przez webjars API (path traversal)
XWiki Rendering: bypass trybu restricted przez zagnieżdżone makra
XWiki Rendering: XSS przez składnię xdom+xml/current w XHTML