Impact
XWiki Platform allows a user who can edit a page to modify that page's rights through the Live Data edit REST API without the normal authorization checks. By granting themselves the script right, the attacker can run arbitrary Velocity scripts or deliver unfiltered HTML and JavaScript to clients. This creates a rise in privileges from edit rights to full script execution,, integrity, and availability of the XWiki instance. The same missing checks can circumvent extension security controls implemented as listeners for UserUpdatingDocumentEvent and related user document events. The weakness is an authorization bypass that permits users to change access controls they should not be able to modify.
Affected Systems
The vulnerability exists in XWiki Platform releases from 13.4‑rc‑1 through 16.10.17, 17.4.10, 17.10.4, and 18.1.0‑rc‑1. All earlier versions within this range are affected until the instance is updated to one of the patched releases.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity. The EPSS score of < 1 exploitation probability, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must be authenticated with page‑edit privileges to exploit the flaw. Once those rights exist, the Live Data endpoint can grant script rights, enabling arbitrary script execution or injection of malicious HTML and JavaScript across the site. The impact scales with the privileges granted to the attacker and could affect the entire XWiki instance.
OpenCVE Enrichment
Github GHSA