XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means that any user with comment right can use the async macro to make it execute any wiki content with the right of superadmin. This has been patched in XWiki 14.9, 14.4.6, and 13.10.10. The only known workaround consists of applying a patch and rebuilding and redeploying `org.xwiki.platform:xwiki-platform-rendering-async-macro`.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-03-02T18:28:52.037Z

Updated: 2023-03-02T18:28:52.037Z

Reserved: 2023-02-23T23:22:58.572Z


Link: CVE-2023-26471

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-03-02T19:15:11.137

Modified: 2023-03-13T16:31:00.973


Link: CVE-2023-26471

JSON object: View

cve-icon Redhat Information

No data.