Description
application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on the rights that a user has over a document, they should be able to open the office attachments files in view or edit mode. Currently, if a user opens an attachment file in edit mode in collabora, this right will be preserved for all future users, until the editing session is closes, even if some of them have only view right. Collabora server is the one issuing this request and it seems that the `userCanWrite` query parameter is cached, even if, for example, token is not. This issue has been patched in version 1.3.
References (1)
Core 1
Core References
Exploit, Patch x_refsource_confirm
https://github.com/xwikisas/application-collabora/security/advisories/GHSA-mvq3-xxg2-rj57
Scores
CVSS v3
7.3
EPSS
0.0032
EPSS Percentile
54.7%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (1)
xwiki/application-collabora
< 1.3
Published
Nov 09, 2023
Tracked Since
Feb 18, 2026