First published: Wed Aug 23 2023(Updated: )
### Impact The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/programming right, thus compromising the confidentiality, integrity and availability of the whole XWiki installation. To reproduce, the XWiki syntax `[[image:path:/xwiki/bin/create/Foo/WebHome?template=&parent=Main.WebHome&title=$services.logging.getLogger(%22foo%22).error(%22Script%20executed!%22)]]` can be added to any place that supports XWiki syntax like a comment. When a user with script right views this image and a log message `ERROR foo - Script executed!` appears in the log, the XWiki installation is vulnerable. ### Patches This has been patched in XWiki 14.10.9 and 15.4RC1 by requiring a CSRF token for the actual page creation. ### Workarounds There are no known workarounds. ### References * https://jira.xwiki.org/browse/XWIKI-20849 * https://github.com/xwiki/xwiki-platform/commit/4b20528808d0c311290b0d9ab2cfc44063380ef7
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xwiki Xwiki | <14.10.9 | |
Xwiki Xwiki | =15.0 | |
Xwiki Xwiki | =15.0-rc1 | |
Xwiki Xwiki | =15.1 | |
Xwiki Xwiki | =15.1-rc1 | |
Xwiki Xwiki | =15.2 | |
Xwiki Xwiki | =15.2-rc1 | |
Xwiki Xwiki | =15.3 | |
Xwiki Xwiki | =15.3-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability allows for a CSRF attack, leading to remote code execution and compromising the confidentiality, integrity, and availability of the XWiki installation.
To reproduce the vulnerability, use the XWiki syntax `[[image:...
Versions 15.4-rc-1 and 14.10.9 of XWiki Platform are affected by the vulnerability.
The severity of CVE-2023-40572 is critical, with a CVSS score of 8.
Yes, you can find references for CVE-2023-40572 at the following links: [GitHub Commit](https://github.com/xwiki/xwiki-platform/commit/4b20528808d0c311290b0d9ab2cfc44063380ef7), [GitHub Security Advisory](https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-4f8m-7h83-9f6m), [Jira Ticket](https://jira.xwiki.org/browse/XWIKI-20849).