CVE-2026-48048
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the LiveTableResults, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17. As a workaround, the patch can be applied manually to the wiki page XWiki.LiveTableResultsMacros.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| xwiki | xwiki-platform | >= 6.2.1, < 16.10.17 | affected |
| xwiki | xwiki-platform | >= 17.0.0-rc-1, < 17.4.9 | affected |
| xwiki | xwiki-platform | >= 17.5.0-rc-1, < 17.10.3 | affected |
Weaknesses
- CWE-359: CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rh28-mqj4-8x59
- https://github.com/xwiki/xwiki-platform/commit/c4442716b02ffcdaa9d5e703b1db6203e36456fa
- https://jira.xwiki.org/browse/XWIKI-23875
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.