CVE-2024-45591: XWiki Platform – Unauthorized Document History Access

CVE-2024-45591: XWiki Platform - Unauthorized Document History Access-渗透云记 - 专注于网络安全与技术分享
CVE-2024-45591: XWiki Platform – Unauthorized Document History Access
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-45591: XWiki Platform – Unauthorized Document History Access

漏洞描述

A vulnerability in XWiki Platform's REST API allows unauthorized users to access document history information. The REST API endpoint exposes the history of any page including modification times, version numbers, author details (username and display name), and version comments, regardless of access rights configuration, even on private wikis.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享