CVE-2023-45138

Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution just by inserting an appropriate title when creating a new Change Request. This vulnerability is particularly critical as Change Request aims at being created by user without any particular rights. The vulnerability has been fixed in Change Request 1.9.2. It's possible to workaround the issue without upgrading by editing the document `ChangeRequest.Code.ChangeRequestSheet` and by performing the same change as in the fix commit.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xwiki:change_request:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:26

Type Values Removed Values Added
References () https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4 - Patch () https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4 - Patch
References () https://github.com/xwiki-contrib/application-changerequest/security/advisories/GHSA-f776-w9v2-7vfj - Vendor Advisory () https://github.com/xwiki-contrib/application-changerequest/security/advisories/GHSA-f776-w9v2-7vfj - Vendor Advisory
References () https://jira.xwiki.org/browse/CRAPP-298 - Issue Tracking, Third Party Advisory () https://jira.xwiki.org/browse/CRAPP-298 - Issue Tracking, Third Party Advisory
CVSS v2 : unknown
v3 : 9.6
v2 : unknown
v3 : 10.0

18 Oct 2023, 18:51

Type Values Removed Values Added
First Time Xwiki
Xwiki change Request
References (MISC) https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4 - (MISC) https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4 - Patch
References (MISC) https://jira.xwiki.org/browse/CRAPP-298 - (MISC) https://jira.xwiki.org/browse/CRAPP-298 - Issue Tracking, Third Party Advisory
References (MISC) https://github.com/xwiki-contrib/application-changerequest/security/advisories/GHSA-f776-w9v2-7vfj - (MISC) https://github.com/xwiki-contrib/application-changerequest/security/advisories/GHSA-f776-w9v2-7vfj - Vendor Advisory
CPE cpe:2.3:a:xwiki:change_request:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6

12 Oct 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-12 17:15

Updated : 2024-11-21 08:26


NVD link : CVE-2023-45138

Mitre link : CVE-2023-45138

CVE.ORG link : CVE-2023-45138


JSON object : View

Products Affected

xwiki

  • change_request
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')