CVE-2023-45138

Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution just by inserting an appropriate title when creating a new Change Request. This vulnerability is particularly critical as Change Request aims at being created by user without any particular rights. The vulnerability has been fixed in Change Request 1.9.2. It's possible to workaround the issue without upgrading by editing the document `ChangeRequest.Code.ChangeRequestSheet` and by performing the same change as in the fix commit.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xwiki:change_request:*:*:*:*:*:*:*:*

History

18 Oct 2023, 18:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6
First Time Xwiki change Request
Xwiki
CPE cpe:2.3:a:xwiki:change_request:*:*:*:*:*:*:*:*
References (MISC) https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4 - (MISC) https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4 - Patch
References (MISC) https://jira.xwiki.org/browse/CRAPP-298 - (MISC) https://jira.xwiki.org/browse/CRAPP-298 - Issue Tracking, Third Party Advisory
References (MISC) https://github.com/xwiki-contrib/application-changerequest/security/advisories/GHSA-f776-w9v2-7vfj - (MISC) https://github.com/xwiki-contrib/application-changerequest/security/advisories/GHSA-f776-w9v2-7vfj - Vendor Advisory

12 Oct 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-12 17:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-45138

Mitre link : CVE-2023-45138

CVE.ORG link : CVE-2023-45138


JSON object : View

Products Affected

xwiki

  • change_request
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')