Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5.
Remediation
References
Related Vulnerabilities
Django Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0472)
WordPress Plugin Simply Static Arbitrary File Download (1.6.2)
Oracle Application Server Other Vulnerability (CVE-2005-3452)
CubeCart Session Fixation Vulnerability (CVE-2021-33394)
Apache HTTP Server CVE-2003-0789 Vulnerability (CVE-2003-0789)