Description
XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view rights provided on a space of a deleted document are properly checked. The problem has been patched in XWiki 14.10 by checking the rights of current user: only admin and deleter of the document are allowed to view it.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.6.x Cross-Site Scripting (1.6.0 - 1.6.5)
WordPress Plugin Limit Login Attempts Reloaded Security Bypass (2.7.4)
WebLogic CVE-2017-10352 Vulnerability (CVE-2017-10352)
WordPress Plugin WordPress Access Areas Security Bypass (1.3.0)
WordPress Plugin Radio Buttons for Taxonomies Cross-Site Request Forgery (2.0.5)