XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.8 and 16.3.0RC1.
{
"cwe_ids": [
"CWE-80"
]
}[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"21155742351908933010213828537043375122",
"273166470439608780614388405906396775011",
"257802522662050657643952040823402044512",
"229476200234515363868841825713592731625",
"248459148515579882089514317394450952605",
"225805416268014336793980877945859740920",
"3069364051456673488025796464750280495",
"193224163244773286660232109753531851063",
"288403268691264797168806873703562657529",
"153420000428550045532760707455047246693",
"227030252882608813056940215681387162889",
"136434656779224626169361800611357890889",
"158834344623340583666815344593027121470",
"193224163244773286660232109753531851063",
"1332571388758168851027022748764812579",
"44905972275475979883088220851302570980",
"78840683487569123086098334486816543326",
"231642458328221174279473971436277455798",
"171319635799392374080661634281621187601",
"37375601237918814507296090296663130447"
]
},
"target": {
"file": "xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-test/xwiki-platform-flamingo-skin-test-docker/src/test/it/org/xwiki/flamingo/test/docker/EditIT.java"
},
"signature_version": "v1",
"id": "CVE-2024-41947-2dd52f24",
"deprecated": false,
"source": "https://github.com/xwiki/xwiki-platform/commit/e00e159d3737397eebd1f6ff925c1f5cb7cdec34"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"21155742351908933010213828537043375122",
"273166470439608780614388405906396775011",
"257802522662050657643952040823402044512",
"229476200234515363868841825713592731625",
"248459148515579882089514317394450952605",
"225805416268014336793980877945859740920",
"3069364051456673488025796464750280495",
"193224163244773286660232109753531851063",
"288403268691264797168806873703562657529",
"153420000428550045532760707455047246693",
"227030252882608813056940215681387162889",
"136434656779224626169361800611357890889",
"158834344623340583666815344593027121470",
"193224163244773286660232109753531851063",
"1332571388758168851027022748764812579",
"44905972275475979883088220851302570980",
"78840683487569123086098334486816543326",
"231642458328221174279473971436277455798",
"171319635799392374080661634281621187601",
"37375601237918814507296090296663130447"
]
},
"target": {
"file": "xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-test/xwiki-platform-flamingo-skin-test-docker/src/test/it/org/xwiki/flamingo/test/docker/EditIT.java"
},
"signature_version": "v1",
"id": "CVE-2024-41947-4613ad70",
"deprecated": false,
"source": "https://github.com/xwiki/xwiki-platform/commit/821d43ec45e67d45a6735a0717b9b77fffc1cd9f"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "193954538563252037518932632250007806634",
"length": 10868.0
},
"target": {
"file": "xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-test/xwiki-platform-flamingo-skin-test-docker/src/test/it/org/xwiki/flamingo/test/docker/EditIT.java",
"function": "editWithConflict"
},
"signature_version": "v1",
"id": "CVE-2024-41947-ceeb177d",
"deprecated": false,
"source": "https://github.com/xwiki/xwiki-platform/commit/821d43ec45e67d45a6735a0717b9b77fffc1cd9f"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "193954538563252037518932632250007806634",
"length": 10868.0
},
"target": {
"file": "xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-test/xwiki-platform-flamingo-skin-test-docker/src/test/it/org/xwiki/flamingo/test/docker/EditIT.java",
"function": "editWithConflict"
},
"signature_version": "v1",
"id": "CVE-2024-41947-f82bc77e",
"deprecated": false,
"source": "https://github.com/xwiki/xwiki-platform/commit/e00e159d3737397eebd1f6ff925c1f5cb7cdec34"
}
]