S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Misconfiguration·Updated Dec 3, 2024

CVE-2022-24819 Scanner

CVE-2022-24819 Scanner - Information Disclosure vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-24819
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
xwiki-platformby xwiki
< 4.3
Updated Aug 22, 2026View on NVD →
Detail

XWiki is a powerful open-source wiki platform used by businesses and developers for managing and sharing knowledge. It is designed to provide collaborative tools for documentation, project tracking, and data organization. XWiki is popular in enterprise environments for its customization capabilities and wide range of extensions. The software is used across industries like technology, education, and government to create dynamic knowledge bases and wikis. Its modular architecture allows users to adapt the platform to suit various needs. With support for scripting and APIs, XWiki enables the development of custom features and integrations.

The vulnerability involves unauthorized access to sensitive user information through a publicly accessible URL in XWiki. This flaw allows an unauthenticated attacker to retrieve a list of users and their full names. The issue affects versions earlier than 12.10.11, 13.4.4, and 13.9-rc-1. Information disclosure of this type could be leveraged to identify valid user accounts, making the system more susceptible to attacks like brute force or phishing. This vulnerability primarily impacts the confidentiality of the data, making sensitive user information exposed to potential misuse.

The technical details of the vulnerability lie in an endpoint that provides user data without proper authentication checks. Specifically, endpoints such as `/bin/login/XWikiLogin?xpage=uorgsuggest&uorg=user` are exposed, allowing attackers to retrieve user details in JSON or XML formats. Matchers in this scanner identify key elements like "value," "label," and "icon" in the response, confirming the presence of the flaw. The vulnerability stems from insufficient restrictions on specific paths, enabling malicious actors to gather data intended for internal use.

If exploited, this vulnerability can lead to the exposure of user details, facilitating targeted attacks such as social engineering or account compromise. In environments with sensitive user information, the impact could extend to reputational damage and compliance violations. Organizations relying on XWiki for enterprise knowledge management could face serious consequences if attackers leverage this vulnerability to infiltrate other systems or access critical information.

REFERENCES

Solution Advice
  • Upgrade XWiki to version 12.10.11, 13.4.4, or 13.9-rc-1, or later.
  • Restrict public access to sensitive URLs by applying authentication checks.
  • Review and adjust access controls for user data endpoints.
  • Monitor logs for unauthorized access attempts to endpoints.
  • Implement regular vulnerability assessments and patch management.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.