PT-2023-4802 · Unknown · Ckeditor Integration Ui+1

·

CVE-2023-22457

·

Publicado

2023-01-04

·

Atualizado

2023-01-10

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CKEditor Integration UI versions prior to 1.64.3 XWiki Platform versions prior to 14.6 RC1
Description The issue is related to insufficient authentication checks for executed requests in the CKEditor integration interface of the XWiki platform. This allows an attacker to execute a Cross-Site Request Forgery (CSRF) attack, potentially leading to arbitrary remote code execution. If a privileged user with programming rights is tricked into executing a GET request to the CKEditor.HTMLConverter document with certain parameters, the attacker could gain rights, access private information, or impact the availability of the wiki.
Recommendations For CKEditor Integration UI versions prior to 1.64.3, upgrade to version 1.64.3 or later. For XWiki Platform versions prior to 14.6 RC1, upgrade to version 14.6 RC1 or later. As a temporary workaround, consider restricting access to the CKEditor.HTMLConverter document to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05265
CVE-2023-22457
GHSA-6MJP-2RM6-9G85

Produtos afetados

Ckeditor Integration Ui
Xwiki Platform