XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-0846 XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.
Github GHSA Github GHSA GHSA-3738-p9x3-mv9r XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-05T21:21:51.637Z

Reserved: 2023-02-23T23:22:58.573Z

Link: CVE-2023-26474

cve-icon Vulnrichment

Updated: 2024-08-02T11:53:54.184Z

cve-icon NVD

Status : Modified

Published: 2023-03-02T19:15:11.390

Modified: 2024-11-21T07:51:35.083

Link: CVE-2023-26474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.