-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from an insecure include directive in XWiki's ClassSheet template. The patch added 'author="target"' to the {{include}} macro, indicating the original implementation lacked proper authorization context for included content. This allowed attackers to bind malicious code to their profile page and execute it with elevated privileges by leveraging the ClassSheet's authority through DocumentSheetBinding. The file modification in the commit directly correlates with the vulnerability description and CWE-863 (Incorrect Authorization).
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.xwiki.platform:xwiki-platform-test-ui | maven | >= 3.3-milestone-3, < 14.10.4 | 14.10.4 |
Ongoing coverage of React2Shell