Threat Advisory

Cross-Site Request Forgery Flaw Deletes Messages in XWiki Discussions Server

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity Cross-Site Request Forgery (CSRF) vulnerability, tracked as CVE-2023-37465 with a CVSS score of 6.5, has been identified in the org.xwiki.contrib:discussions-server package. This flaw allows an attacker to delete messages by forging a request through user interaction, potentially impacting integrity via environment template management API. The attack vector is network-based (AV:N), and the attack complexity is low (AC:L). User interaction is required for exploitation (UI:R), but no sensitive data can be accessed or compromised (C:N). However, integrity of the system may be impacted (I:H). This vulnerability affects versions prior to 2.0-rc-1.

RECOMMENDATION:

We recommend you to update org.xwiki.contrib:discussions-server to version 2.0-rc-1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity Cross-Site Request Forgery (CSRF) vulnerability, tracked as CVE-2023-37465 with a CVSS score of 6.5, has been identified in the org.xwiki.contrib:discussions-server package. This flaw allows an attacker to delete messages by forging a request through user interaction, potentially impacting integrity via environment template management API. The attack vector is network-based (AV:N), and the attack complexity is low (AC:L). User interaction is required for exploitation (UI:R), but no sensitive data can be accessed or compromised (C:N). However, integrity of the system may be impacted (I:H). This vulnerability affects versions prior to 2.0-rc-1.

RECOMMENDATION:

We recommend you to update org.xwiki.contrib:discussions-server to version 2.0-rc-1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu