CVE-2023-48292

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 20, 2023
Updated: Nov 29, 2023
CWE ID 352

Summary

CVE-2023-48292 is a cross-site request forgery (CSRF) vulnerability affecting the XWiki Admin Tools Application, starting from version 4.4. By tricking an administrator into loading a malicious URL containing shell commands, an attacker can execute arbitrary commands on the server. This issue is significant as it allows an attacker to compromise the integrity and confidentiality of the entire XWiki installation. Attack vectors include comments on wiki pages, where an attacker can embed a URL with the shell command. The vulnerability is further compounded by the fact that the output of the command is susceptible to XWiki syntax injection, enabling Groovy code execution. Version 4.5.1 of the admin tools addresses this issue by adding a form token check. Alternative workarounds include applying the patch manually to affected pages or deleting the `Admin.RunShellCommand` document if shell command execution is not required.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share