
PEACH
Uma estrutura de isolamento de inquilino
CVE-2023-37465 is a Cross-Site Request Forgery (CSRF) vulnerability in the XWiki Discussion Extension (org.xwiki.contrib:discussions-server) that allows an attacker to forge requests to delete discussion messages. It affects all versions prior to 2.0-rc-1 (specifically versions below 1.1 per the repository advisory). The vulnerability was published on July 23, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, XWiki Advisory).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), meaning the discussions-server component does not sufficiently verify that incoming requests to delete messages were intentionally initiated by the authenticated user. An attacker can craft a malicious web page or link that, when visited by an authenticated XWiki user, silently sends a forged delete-message request to the vulnerable endpoint on the target XWiki instance. No privileges are required on the attacker's side, but user interaction (victim visiting a malicious page) is necessary. The specific vulnerable endpoint and request format are referenced in the upstream Jira issue DISCUSSION-22 (GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to permanently delete discussion messages on behalf of an authenticated victim, resulting in a high integrity impact with no confidentiality or availability impact. This could be used to disrupt collaborative workflows, erase important discussion content, or perform targeted content destruction on XWiki instances using the Discussion Extension (GitHub Advisory, XWiki Advisory).
org.xwiki.contrib:discussions-server) at a version below 2.0-rc-1.Referer headers pointing to external or unknown domains.The vulnerability has been patched in version 2.0-rc-1 of the XWiki Discussion Extension (org.xwiki.contrib:discussions-server). There is no documented workaround other than upgrading to the patched version. Administrators should update the Discussion Extension to 2.0-rc-1 or later as soon as possible (GitHub Advisory, XWiki Advisory).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."