CVE-2023-26476: Two XWiki Platform UIs Expose Sensitive Information to an Unauthorized Actor
XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to LiveTableResults and WikisLiveTableResultsMacros. The issue can be fixed by upgrading to versions 14.7-rc-1, 13.4.4, or 13.10.9 and higher, or in version >= 3.2M3 by applying the patch manually on LiveTableResults and WikisLiveTableResultsMacros.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26476?
CVE-2023-26476 has been classified as a moderate severity vulnerability that allows password content to be inferred.
How do I fix CVE-2023-26476?
To fix CVE-2023-26476, upgrade to XWiki versions 14.7-rc-1, 13.4.4, or 13.10.9 and higher.
What versions of XWiki are affected by CVE-2023-26476?
CVE-2023-26476 affects XWiki versions between 3.2-milestone3 and 14.7, excluding the patched versions.
What specific functionality is exploited in CVE-2023-26476?
CVE-2023-26476 allows attackers to deduce the content of the password fields through repeated calls to LiveTableResults.
Is CVE-2023-26476 a client-side or server-side vulnerability?
CVE-2023-26476 is a server-side vulnerability affecting the XWiki platform.