Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1741 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki. |
Github GHSA |
GHSA-ghcq-472w-vf4h | Incorrect Use of Privileged APIs in org.xwiki.platform.skin.skinx |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T18:17:02.831Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24821
No data.
Status : Modified
Published: 2022-04-08T19:15:08.257
Modified: 2024-11-21T06:51:10.350
Link: CVE-2022-24821
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA