MEDIUM
XWiki Cross-Site Request Forgery (CSRF) for actions on tags
Published Sep 8, 2022
4.3
MEDIUMCVSS 3.1
EPSS 0.42%
Description
XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As a workaround, one may locally modify the `documentTags.vm` template in one's filesystem, to apply the changes exposed there.
Affected products
-
- Version >= 14.0, < 14.3StatusaffectedConstraints-
- Version >= 2.0-milestone-1, < 13.10.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Xwiki | Xwiki-Platform | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6813 Advisory
- https://github.com/advisories/GHSA-fxwr-4vq9-9vhj Advisory
- https://github.com/xwiki/xwiki-platform/commit/7ca56e40cf79a468cea54d3480b6b403f259f9ae x_refsource_MISCPatchThird Party Advisory
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-fxwr-4vq9-9vhj x_refsource_CONFIRMPatchThird Party Advisory
- https://jira.xwiki.org/browse/XWIKI-19550 x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36095
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6813 | Advisory | |
| https://github.com/advisories/GHSA-fxwr-4vq9-9vhj | Advisory | |
| https://github.com/xwiki/xwiki-platform/commit/7ca56e40cf79a468cea54d3480b6b403f259f9ae | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-fxwr-4vq9-9vhj | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://jira.xwiki.org/browse/XWIKI-19550 | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-36095 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 8, 2022
Updated Apr 23, 2025
Reserved Jul 15, 2022
Link CVE-2022-36095
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2022-6813 GHSA-FXWR-4VQ9-9VHJ Assigner GitHub_M
Published Sep 8, 2022
Updated Apr 23, 2025
Exploited since n/a
Link EUVD-2022-6813