XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been fixed in XWiki 17.0.0, 16.4.7, and 16.10.3.
| Software | From | Fixed in |
|---|---|---|
org.xwiki.platform / xwiki-platform-oldcore
|
7.2-milestone-2 | 16.4.7 |
org.xwiki.platform / xwiki-platform-oldcore
|
16.5.0-rc-1 | 16.10.3 |
org.xwiki.platform / xwiki-platform-oldcore
|
17.0.0-rc-1 | 17.0.0 |
| xwiki / xwiki | 7.3 | 16.4.7 |
| xwiki / xwiki | 16.5.0 | 16.10.3 |
| xwiki / xwiki | 7.2-milestone2 | 7.2-milestone2.x |
| xwiki / xwiki | 7.2-milestone3 | 7.2-milestone3.x |
| xwiki / xwiki | 17.0.0-rc1 | 17.0.0-rc1.x |