CVE-2007-4888

XWiki 1.0 B1-1.0 B2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.

References (2)

Core 2
Core References
Various Sources x_refsource_confirm
http://jira.xwiki.org/jira/browse/XWIKI-726
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/40499

Scores

EPSS 0.0006
EPSS Percentile 19.4%

Details

Status published
Products (2)
xwiki/xwiki 1.0_b1
xwiki/xwiki 1.0_b2
Published Sep 14, 2007
Tracked Since Feb 18, 2026