CVE-2022-36090 is a critical access control bypass vulnerability affecting XWiki Platform Old Core versions prior to 13.10.5 and 14.3-rc-1. It allows inactive (disabled or unactivated) users to re-enable themselves or perform actions through certain extension handlers via a REST API call, bypassing intended security restrictions. With a CVSS score of 8.1 (High), this vulnerability has a low attack complexity and requires only low privileges, potentially leading to high impact on confidentiality and integrity. There is currently no evidence of active exploitation, nor are there public exploit codes or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1, < 13.10.5CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.