CVE-2023-37462: XWiki Platform – Remote Code Execution

CVE-2023-37462: XWiki Platform - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2023-37462: XWiki Platform – Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-37462: XWiki Platform – Remote Code Execution

漏洞描述

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is possible to execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The attack works by opening a non-existing page with a name crafted to contain a dangerous payload. It is possible to check if an existing installation is vulnerable

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享