Missing Authorization in XWiki platform - CVE-2022-23621
Published: February 9, 2022 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in XWiki#invokeServletAndReturnAsString when handling servlet path input. A remote privileged user can request a file path within the WAR to disclose sensitive information.
Before XWiki 7.4, the same access was possible with EDIT right instead of SCRIPT right.