Exposure of Resource to Wrong Sphere in XWiki platform - CVE-2023-37911
Published: October 25, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in deleted document revisions when accessing deleted revisions through the diff feature or the REST API. A remote user can request versions such as deleted:1 to disclose sensitive information.
The issue occurs when a document has been deleted and re-created, and can also affect any deleted document if the user can re-create it in the original location.