CVE-2023-45138
XWiki Change Request Application UI XSS and remote code execution through change request title
描述
### Impact It's possible for a user without any specific right to perform script injection and remote code execution just by inserting an appropriate title when creating a new Change Request. This vulnerability is particularly critical as Change Request aims at being created by user without any particular rights. ### Patches The vulnerability has been fixed in Change Request 1.9.2. ### Workarounds It's possible to workaround the issue without upgrading by editing the document `ChangeRequest.Code.ChangeRequestSheet` and by performing the same change as in the commit: https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4. ### References * JIRA ticket: https://jira.xwiki.org/browse/CRAPP-298 * Commit of the fix: https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki.org](https://jira.xwiki.org/) * Email us at [Security Mailing List](mailto:security@xwiki.org) ### Attribution Thanks Michael Hamann for the report.
如何修補 CVE-2023-45138
要修補 CVE-2023-45138,請將受影響套件升級到下列已修補版本。
- —升級至 1.9.2 或更新版本
CVE-2023-45138 正在被利用嗎?
可能 — EPSS 為 71.2%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 0.11, < 1.9.2
CVSS 分數
| 來源 |
|---|