CVE-2006-7223 describes a vulnerability in XWiki versions 0.9.543 through 0.9.1252 where the PreviewAction function fails to correctly attribute the last modifier of a document. This flaw allows authenticated users without programming rights to execute arbitrary code. By modifying and previewing a document authored by a user with programming rights, an attacker can inject and execute malicious scripts without saving the changes. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity requiring authentication, potentially leading to partial confidentiality, integrity, and availability impacts. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are virtually nonexistent, further indicating a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.543CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:0.9.543:*:*:*:*:*:*:* | ||
0.9.790CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:0.9.790:*:*:*:*:*:*:* | ||
0.9.793CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:0.9.793:*:*:*:*:*:*:* | ||
0.9.840CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:0.9.840:*:*:*:*:*:*:* | ||
0.9.1252CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:0.9.1252:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.