Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, a user can rollback to a previous version of the page to gain rights they don't have anymore. The problem has been patched in XWiki 14.10.17, 15.5.3 and 15.8-rc-1 by ensuring that the rights are checked before performing the rollback.
References (3)
Core 3
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-xh35-w7wg-95v3
Patch x_refsource_misc
https://github.com/xwiki/xwiki-platform/commit/4de72875ca49602796165412741033bfdbf1e680
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.xwiki.org/browse/XWIKI-21257
Scores
CVSS v3
8.0
EPSS
0.0034
EPSS Percentile
56.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-274
Status
published
Products (3)
org.xwiki.platform/xwiki-platform
15.0-rc-1 - 15.5.3Maven
org.xwiki.platform/xwiki-platform-oldcore
1.0 - 14.10.17Maven
xwiki/xwiki
< 14.10.17
Published
Jan 09, 2024
Tracked Since
Feb 18, 2026