CVE-2023-48241 is an information disclosure vulnerability affecting XWiki Platform versions 6.3-milestone-2 through 14.10.14, 15.5.0, and prior to 15.6RC1. The Solr-based search suggestion provider, also used as a JavaScript API, can expose the content of all documents in all wikis to any user, even without proper authorization, by circumventing normal right checks. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-exploitable flaw with low attack complexity that can lead to complete confidentiality compromise. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detecting this high-severity issue, and it has a high FAUCET Risk Score of 98/100.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.4, < 14.10.5CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.5.1CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:6.3:milestone2:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:6.3:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.