← back
CVE-2023-29214

org.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability

CVSS 10 CRITICALEPSS 1.2%CWE-95
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 10EPSS 1.2%KEV nãoPoC Patch
Lifecycle
Apr 16, 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included pages in the IncludedDocuments panel. The problem has been patched on XWiki 14.4.7, and 14.10.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
xwiki · xwiki-platform

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →