Description
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `wikiId` url parameter. The problem has been patched on XWiki 13.10.11, 14.4.7, and 14.10.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1406 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `wikiId` url parameter. The problem has been patched on XWiki 13.10.11, 14.4.7, and 14.10. |
Github GHSA |
GHSA-w7v9-fc49-4qg4 | org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability |
References
History
Thu, 06 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-06T17:05:23.638Z
Reserved: 2023-04-03T13:37:18.455Z
Link: CVE-2023-29211
Updated: 2024-08-02T14:00:15.991Z
Status : Modified
Published: 2023-04-16T07:15:52.873
Modified: 2024-11-21T07:56:43.390
Link: CVE-2023-29211
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA