CVE-2023-48240
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-48240 is a vulnerability affecting the XWiki Platform, a wiki solution. In versions prior to 14.10.15, 15.5.1, and 15.6, and starting from 11.10.1, the platform's rendered diff functionality inadvertently requests and downloads images from other domains during the comparison process. This behavior exposes a serious issue, as the platform unintentionally sends all cookies from the original request along with these image requests. An attacker can exploit this to steal login and session cookies, enabling impersonation of the affected user. Additionally, the vulnerability allows for server-side request forgery and unauthorized access to protected content. The issue has been patched in XWiki 14.10.15, 15.5.1, and 15.6, with improvements including the restriction of image downloads from trusted domains, the sending of cookies only for requests from the same domain, and the implementation of a user-specific cache. As a temporary solution, users can disable the image embedding feature by deleting `xwiki-platform-diff-xml-<version>.jar` from `WEB-INF/lib/`.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xwiki
Affected Vendors
- xwiki