CVE-2022-41929

MEDIUM

Xwiki < 13.10.7 - Missing Authorization

Title source: rule
STIX 2.1

Description

org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users with admin rights. This problem has been patched in XWiki 13.10.7, 14.4.2 and 14.5RC1.

Scores

CVSS v3 4.9
EPSS 0.0043
EPSS Percentile 62.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (6)
org.xwiki.platform/xwiki-platform-oldcore 11.7RC1 - 13.10.7Maven
xwiki/xwiki 11.7 rc1
xwiki/xwiki 14.4.3
xwiki/xwiki 14.4.4
xwiki/xwiki 11.7 - 13.10.7
xwiki/xwiki 14.0.0 - 14.4.2
Published Nov 23, 2022
Tracked Since Feb 18, 2026