A user without Script or Programming right is able to execute script requiring privileges by editing gadget titles in the dashboard.
The issue has been patched in XWiki 12.6.7, 12.10.3 and 13.0RC1.
There's no easy workaround for this issue, it is recommended to upgrade XWiki.
https://jira.xwiki.org/browse/XWIKI-17794
If you have any questions or comments about this advisory: * Open an issue in JIRA * Email us at XWiki security mailing-list
{ "nvd_published_at": "2021-05-28T21:15:00Z", "cwe_ids": [ "CWE-94" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-05-18T16:46:49Z" }