Missing Authorization in XWiki platform - CVE-2022-23617
Published: February 9, 2022 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in page template handling when creating a new page from an existing page used as a template. A remote user can use a page as a template to copy its content into a new page to disclose sensitive information.
Exploitation requires edit rights.