XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the styles properties `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki versions 13.10.11, 14.4.7 and 14.10.

Subscriptions

Vendors Products

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-1398 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the styles properties `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki versions 13.10.11, 14.4.7 and 14.10.
Github GHSA Github GHSA GHSA-vrr8-fp7c-7qgp org.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 06 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-06T17:05:39.297Z

Reserved: 2023-04-12T15:19:33.766Z

Link: CVE-2023-30537

cve-icon Vulnrichment

Updated: 2024-08-02T14:28:51.686Z

cve-icon NVD

Status : Modified

Published: 2023-04-16T08:15:07.817

Modified: 2024-11-21T08:00:22.683

Link: CVE-2023-30537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses