Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-23087

Vulnerabilities in XWiki [Error-based SQL Injection, Reflected XSS x2]

    XMLWordPrintable

Details

    • Bug
    • Resolution: Duplicate
    • Critical
    • None
    • 17.2.0
    • Application
    • Unknown

    Description

      Hello! 

      Researchers of cybersecurity company have discovered vulnerabilities in XWiki. Vulnerability Research Report is attached to this issue.

      Positive Technologies plans to release a database update for its products and a publication about the discovered vulnerabilities within the next 90 days from the date of sending this message, so please answer the following questions:

      1. When and in what version will you fix the vulnerabilities described in our Report? (date, version)
      2. If it is not possible to release a patch in the next 90 days, then please indicate the expected release date of the patch (month).
      3. Users of the product XWiki, who are our Clients, use the CVE-ID in the vulnerability management process. Therefore, we ask you to provide the CVE-ID for the vulnerabilities that we submitted to you.

      https://global.ptsecurity.com/policies/positive-coordinated-vulnerability-disclosure-policy

      Thank you for your cooperation.

      Attachments

        Issue Links

          Activity

            People

              MichaelHamann Michael Hamann
              0day zeroday
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: