Missing Authorization in XWiki platform - CVE-2022-41937
Published: November 21, 2022 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to modify any page of the wiki.
The vulnerability exists due to missing authorization in the filter stream converter application when importing a crafted XAR package. A remote user can import a crafted XAR package to modify any page of the wiki.
Exploitation requires view access.