Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the styles properties `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki versions 13.10.11, 14.4.7 and 14.10.
Published: 2023-04-16
Score: 9.9 Critical
EPSS: 29.4% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-1398 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the styles properties `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki versions 13.10.11, 14.4.7 and 14.10.
Github GHSA Github GHSA GHSA-vrr8-fp7c-7qgp org.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalation
History

Thu, 06 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-06T17:05:39.297Z

Reserved: 2023-04-12T15:19:33.766Z

Link: CVE-2023-30537

cve-icon Vulnrichment

Updated: 2024-08-02T14:28:51.686Z

cve-icon NVD

Status : Modified

Published: 2023-04-16T08:15:07.817

Modified: 2024-11-21T08:00:22.683

Link: CVE-2023-30537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses