XMLWordPrintable

Details

    • Unknown
    • N/A
    • N/A

    Description

      SUBMISSION REFERENCES

      RESEARCHER INFORMATION

      • Submitter: renniepak

      SUBMISSION INFORMATION

      • Created at: Wed, 16 Nov 2022 11:12:24 GMT
      • Submission status: Archived

      REPORT CONTENT

      I found another RCE in the comments that can be executed by any unprivileged user.

        1. Reproduction

      1. Login to Xwiki and navigate to a random page. For example: https://intigriti.xwiki.com/xwiki/bin/view/Help/
      2. Append `?viewer=comments` to the url to view the comment section.
      3. Click the `Comment` button and next the `Source` button.
      4. Enter the following payload:

      ```
      cachepython}}import subprocess as A;print(A.check_output('id', shell=True)){{/python/cache
      ```

      5. Click `add comment`

        1. Result

      The resulting page will execute the code and print it to screen.

      {273319}

      Attachments

        Issue Links

          Activity

            People

              MichaelHamann Michael Hamann
              intigriti Intigriti Integration
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: