Exposure of Resource to Wrong Sphere in XWiki platform - CVE-2023-29208
Published: April 12, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in deleted document view handling when viewing deleted documents. A remote attacker can access a deleted document containing view rights to disclose sensitive information.
Only deleted documents that contain view rights are affected; view rights provided on a space of a deleted document are properly checked.