CVE-2022-41928
Last modified
CVE-2022-41928 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properties. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properties. This has been patched in versions 13.10.7, 14.4.2, and 14.5. The issue can be fixed on a running wiki by updating `XWiki.AttachmentSelector` with the versions below: - 14.5-rc-1+: https://github.com/xwiki/xwiki-platform/commit/eb15147adf94bddb92626f862c1710d45bcd64a7#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23 - 14.4.2+: https://github.com/xwiki/xwiki-platform/commit/c02f8eb1f3c953d124f2c097021536f8bc00fa8d#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23 - 13.10.7+: https://github.com/xwiki/xwiki-platform/commit/efd0df0468d46149ba68b66660b93f31b6318515#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Xwiki | Xwiki | > 5.0, < 13.10.7 | — |
| Xwiki | Xwiki | >= 14.0.0, < 14.4.2 | — |
| Xwiki | Xwiki | 5.0 | Milestone1 |
| Xwiki | Xwiki | 14.4.3 | — |
| Xwiki | Xwiki | 14.4.4 | — |
References
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9hqh-fmhg-vq2jExploit, Patch, Third Party Advisory
- https://jira.xwiki.org/browse/XWIKI-19800Exploit, Issue Tracking, Vendor Advisory
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9hqh-fmhg-vq2jExploit, Patch, Third Party Advisory
- https://jira.xwiki.org/browse/XWIKI-19800Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41928?
How severe is CVE-2022-41928?
How do I fix CVE-2022-41928?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-41922`yiisoft/yii` before version 1.1.27 are vulnerable to Remote…9.8
- CVE-2022-41923Grails Spring Security Core plugin is vulnerable to privileg…9.8
- CVE-2022-41924A vulnerability identified in the Tailscale Windows client a…9.6
- CVE-2022-41925A vulnerability identified in the Tailscale client allows a …8.8
- CVE-2022-41926Nextcould talk android is the android OS implementation of t…5.5
- CVE-2022-41927XWiki Platform is vulnerable to Cross-Site Request Forgery (…7.4
- CVE-2022-41929org.xwiki.platform:xwiki-platform-oldcore is missing authori…4.9
- CVE-2022-4193Insufficient policy enforcement in File System API in Google…8.8
- CVE-2022-41930org.xwiki.platform:xwiki-platform-user-profile-ui is missing…8.2
- CVE-2022-41931xwiki-platform-icon-ui is vulnerable to Improper Neutralizat…8.8
- CVE-2022-41932XWiki Platform is a generic wiki platform offering runtime s…5.3
- CVE-2022-41933XWiki Platform is a generic wiki platform offering runtime s…6.5
Are you affected by CVE-2022-41928?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
