GHSA-8xhr-x3v8-rghj
CRITICALCVE-2023-40573XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job script to a document doesn't modify the content author. Together with a CSRF vulnerability in the job scheduler, this can be exploited for remote code execution by an attacker with edit right on the wiki.
- Affected
- >= 1.3
- Fixed in
- not stated
- Weakness
- CWE-284
- Published
- 2023-08-23
- Source
- github