XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in all other places where short text properties are displayed, e.g., in apps created using Apps Within Minutes that use a short text field. The problem has been patched on versions 13.10.9, 14.4.4, 14.7RC1.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2023-0944 | XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in all other places where short text properties are displayed, e.g., in apps created using Apps Within Minutes that use a short text field. The problem has been patched on versions 13.10.9, 14.4.4, 14.7RC1. | 
  Github GHSA | 
                GHSA-8cw6-4r32-6r3h | XWiki Platform may allow privilege escalation to programming rights via user's first name | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Wed, 05 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-05T20:39:15.118Z
Reserved: 2023-02-17T22:44:03.151Z
Link: CVE-2023-26055
Updated: 2024-08-02T11:39:06.565Z
Status : Modified
Published: 2023-03-02T19:15:10.867
Modified: 2024-11-21T07:50:40.323
Link: CVE-2023-26055
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA