Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1020 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display the content of any file on the XWiki server host. This vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10-rc-1. Users are advised to upgrade. Users unable to upgrade may apply the patch `e3527b98fd` manually. |
Github GHSA |
GHSA-gx4f-976g-7g6v | XWiki Platform vulnerable to data leak via Improper Restriction of XML External Entity Reference |
Tue, 25 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T15:00:30.911Z
Reserved: 2023-03-01T19:03:56.633Z
Link: CVE-2023-27480
Updated: 2024-08-02T12:09:43.503Z
Status : Modified
Published: 2023-03-07T19:15:12.663
Modified: 2024-11-21T07:52:59.377
Link: CVE-2023-27480
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA