S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-48241 Scanner

CVE-2023-48241 Scanner - Information Disclosure vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-48241
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki exposes the content of all documents of all wikis to anybody who has access to it, by default it is public. This exposes all information stored in the wiki (but not some protected information like password hashes). While there is a right check normally, the right check can be circumvented by explicitly requesting fields from Solr that don't include the data for the right check. This has been fixed in XWiki 15.6RC1, 15.5.1 and 14.10.15 by not listing documents whose rights cannot be checked. No known workarounds are available.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
xwiki-platformby xwiki
>= 6.3-milestone-2, < 14.10.15
Updated Aug 22, 2026View on NVD →
Detail

XWiki is a powerful open-source wiki platform that is widely used by organizations and communities to create collaborative content. It provides a rich feature set allowing users to organize, edit, and share documents and information seamlessly. The platform is implemented using Java and offers flexible configurations and extensibility, making it suitable for various use cases. XWiki users can build intranets, knowledge bases, and asset management systems, benefiting from its intuitive user interface. However, ensuring the security of information stored in XWiki is crucial as it often contains sensitive and collaborative data. XWiki administrators regularly monitor updates to mitigate potential vulnerabilities.

Information Disclosure vulnerabilities allow unauthorized access to sensitive information that should not be publicly available. This vulnerability specifically enables attackers to exploit a flaw in XWiki's Solr-based search suggestion provider, potentially exposing all documents across wikis. By default, sensitive data stored in wikis can be accessed if adequate protections are not enforced due to incorrect right checks. A successful exploit of this vulnerability gives attackers access to significant data without the appropriate permissions. Maintaining tight access control and visibility over information access is essential to prevent data leakage.

The identified vulnerability involves circumventing the default data access checks in XWiki's Solr search provider. When certain Solr fields are requested, the framework bypasses checks that should restrict data access, inadvertently allowing the exposure of sensitive document information. One can exploit this flaw using specific query parameters in a URL to retrieve unauthorized data. Specifically, the use of fields such as 'title_', 'reference', and 'doccontentraw_' in a crafted URL can lead to the exposure of sensitive document content.

If not remediated, exploitation of this vulnerability can allow attackers to gather sensitive information that could be used for malicious purposes, such as identity theft, corporate espionage, or further attacks weakening the system's security posture. The exposure of confidential data could severely impact organizational reputation, legal standing, and operational security. Unauthorized information dissemination can lead to financial, legal, and reputational consequences, emphasizing the need for robust security measures and timely vulnerability management.

REFERENCES

Solution Advice
  • Update XWiki to versions 15.6RC1, 15.5.1, or 14.10.15 to apply the security patch addressing this vulnerability.
  • Review and restrict access permissions within the wiki to ensure only authorized users have access to sensitive data.
  • Implement monitoring and logging to detect unauthorized access attempts and ensure prompt incident response.
  • Conduct regular security assessments and vulnerability scans to identify and mitigate potential exposures.
  • Educate users and administrators about best practices for data security and the importance of keeping software up to date.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.