CVE-2023-46732: XWiki < 14.10.14 - Cross-Site Scripting

CVE-2023-46732: XWiki < 14.10.14 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2023-46732: XWiki < 14.10.14 - Cross-Site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-46732: XWiki < 14.10.14 – Cross-Site Scripting

漏洞描述

XWiki is vulnerable to reflected cross-site scripting (Rxss) via the rev parameter that is used in the content of the content menu without escaping. If an attacker can convince a user to visit a link with a crafted parameter, this allows the attacker to execute arbitrary actions in the name of the user, including remote code (Groovy) execution in the case of a user with programming right, compromising the confidentiality, integrity and availability of the whole XWiki installation.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享