Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2019-2887 Vulnerability (CVE-2019-2887)
PostgreSQL Other Vulnerability (CVE-2012-1618)
WordPress Plugin All 404 Redirect to Homepage Cross-Site Scripting (1.21)
Oracle Application Server Other Vulnerability (CVE-2002-0565)
WordPress Plugin WP Support Plus Responsive Ticket System PHP Object Injection (9.0.3)