Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution just by inserting an appropriate title when creating a new Change Request. This vulnerability is particularly critical as Change Request aims at being created by user without any particular rights. The vulnerability has been fixed in Change Request 1.9.2. It's possible to workaround the issue without upgrading by editing the document `ChangeRequest.Code.ChangeRequestSheet` and by performing the same change as in the fix commit.
History

Wed, 18 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-10-12T16:22:10.459Z

Updated: 2024-09-18T15:12:51.620Z

Reserved: 2023-10-04T16:02:46.329Z

Link: CVE-2023-45138

cve-icon Vulnrichment

Updated: 2024-08-02T20:14:19.319Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-12T17:15:09.900

Modified: 2023-10-18T18:51:35.237

Link: CVE-2023-45138

cve-icon Redhat

No data.