XWiki
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*
- >= 4.2-milestone-2, < 18.0.0-rc-1
- >= 4.2-milestone-2, < 17.10.3
- >= 4.2-milestone-2, < 17.4.9
- >= 4.2-milestone-2, < 16.10.17
A path traversal vulnerability has been identified in XWiki Platform versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17. This vulnerability allows unauthorized access to configuration files by exploiting the 'resources' parameter in the 'ssx' and 'jsx' endpoints, using leading slashes to navigate outside of the intended directory. The issue has been reported to occur on Tomcat servers.
Exploitation of this vulnerability allows for unauthorized access to sensitive configuration files, including those containing administrative passwords.
The vulnerability can be reproduced by sending a request to the 'ssx' or 'jsx' endpoints with a 'resources' parameter that includes a path traversal payload, such as leading slashes followed by '../' sequences, to navigate to sensitive files like 'xwiki.cfg' located in the 'WEB-INF' directory.
Users can upgrade to XWiki versions 18.1.0-rc-1, 17.10.3, 17.4.9, or 16.10.17 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.