{"id":"CVE-2006-7223","aliases":[],"url":"https://o3.security/vulnerability/CVE-2006-7223","summary":"XWiki Remote Code Execution","details":"PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.","published":"2022-05-01T07:45:42Z","modified":"2024-02-12T17:26:38.849761Z","cvss":null,"epss":{"score":0.01519,"percentile":0.72613,"asOf":"2026-08-21"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"1.0B1"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/c44172a3556d12b62c0d793ab18475e5e13d7120","label":"xwiki/xwiki-platform@c44172a"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-7223"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/c44172a3556d12b62c0d793ab18475e5e13d7120"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"},{"type":"WEB","url":"https://web.archive.org/web/20080616064908/http://jira.xwiki.org/jira/browse/XWIKI-366"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-12T17:26:38.849761Z"}}