XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The same vulnerability can also be exploited in other contexts where the `display` method on a document is used to display a field with wiki syntax, for example in applications created using `App Within Minutes`. This has been patched in XWiki 13.10.11, 14.4.8, 14.10.2 and 15.0RC1. There is no workaround apart from upgrading.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-04-18T23:09:46.711Z
Updated: 2024-08-02T14:07:46.224Z
Reserved: 2023-04-07T18:56:54.629Z
Link: CVE-2023-29523
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-19T00:15:08.987
Modified: 2024-11-21T07:57:13.700
Link: CVE-2023-29523
Redhat
No data.