6.5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
0.001 Low
EPSS
Percentile
37.0%
This issue impacts only XWiki with the Ratings API installed.
The Rating Script Service expose an API to perform SQL requests without escaping the from and where search arguments.
This might lead to an SQL script injection quite easily for any user having Script rights on XWiki.
The problem has been patched in XWiki 12.9RC1.
The only workaround besides upgrading XWiki would be to uninstall the Ratings API in XWiki from the Extension Manager.
https://jira.xwiki.org/browse/XWIKI-17662
If you have any questions or comments about this advisory:
CPE | Name | Operator | Version |
---|---|---|---|
org.xwiki.platform:xwiki-platform-ratings-api | lt | 12.9 |
6.5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
0.001 Low
EPSS
Percentile
37.0%