CVE-2021-21380
Rating Script Service expose XWiki to SQL injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Rating Script Service expose an API to perform SQL requests without escaping the from and where search arguments. This might lead to an SQL script injection quite easily for any user having Script rights on XWiki. The problem has been patched in XWiki 12.9RC1. The only workaround besides upgrading XWiki would be to uninstall the Ratings API in XWiki from the Extension Manager.
XWiki Platform es una plataforma wiki genérica que ofrece servicios en tiempo de ejecución para aplicaciones creadas sobre ella. En las versiones afectadas de la plataforma XWiki (y solo aquellas con la API Ratings instalada), el Rating Script Service expone una API para llevar a cabo peticiones SQL sin escapar de los argumentos de búsqueda desde y dónde. Esto podría conllevar a una inyección de Script SQL con bastante facilidad para cualquier usuario que tenga derechos de Script en XWiki. El problema ha sido parcheado en XWiki versión 12.9RC1. La única solución alternativa además de actualizar XWiki sería desinstalar la API Ratings en XWiki desde el Extension Manager
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-22 CVE Reserved
- 2021-03-23 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-79rg-7mv3-jrr5 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jira.xwiki.org/browse/XWIKI-17662 | 2021-03-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xwiki Search vendor "Xwiki" | Xwiki Search vendor "Xwiki" for product "Xwiki" | >= 6.4.1 <= 12.8 Search vendor "Xwiki" for product "Xwiki" and version " >= 6.4.1 <= 12.8" | - |
Affected
| ||||||
Xwiki Search vendor "Xwiki" | Xwiki Search vendor "Xwiki" for product "Xwiki" | 6.4 Search vendor "Xwiki" for product "Xwiki" and version "6.4" | - |
Affected
| ||||||
Xwiki Search vendor "Xwiki" | Xwiki Search vendor "Xwiki" for product "Xwiki" | 6.4 Search vendor "Xwiki" for product "Xwiki" and version "6.4" | milestone3 |
Affected
| ||||||
Xwiki Search vendor "Xwiki" | Xwiki Search vendor "Xwiki" for product "Xwiki" | 6.4 Search vendor "Xwiki" for product "Xwiki" and version "6.4" | rc1 |
Affected
|