Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-26055
HistoryMar 02, 2023 - 7:15 p.m.

Code injection

2023-03-0219:15:00
PRIOn knowledge base
www.prio-n.com
5
xwiki commons
code injection
vulnerability
patched
versions 13.10.9
14.4.4
14.7rc1
short text field

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.6%

XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in all other places where short text properties are displayed, e.g., in apps created using Apps Within Minutes that use a short text field. The problem has been patched on versions 13.10.9, 14.4.4, 14.7RC1.

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.6%

Related for PRION:CVE-2023-26055