Code injection in display method used in user profiles in xwiki-platform
Vulnerability Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The same vulnerability can also be exploited in other contexts where the `display` method on a document is used to display a field with wiki syntax, for example in applications created using `App Within Minutes`. This has been patched in XWiki 13.10.11, 14.4.8, 14.10.2 and 15.0RC1. There is no workaround apart from upgrading.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-29523
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-x764-ff8r-9hpx
- https://github.com/xwiki/xwiki-platform/commit/0d547181389f7941e53291af940966413823f61c
- https://extensions.xwiki.org/xwiki/bin/view/Extension/App%20Within%20Minutes%20Application
- https://jira.xwiki.org/browse/XWIKI-20327
More from xwiki
View All →Affected Vendor
xwiki
View all reports →