Back to overview

CVE-2023-26472

CRITICAL
10.0
CVSS 3.1
Description
XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even through the user profile for users not having edit right. The issue has been patched in XWiki 14.9, 14.4.6, and 13.10.10. An available workaround is to fix the bug in the page `IconThemesCode.IconThemeSheet` by applying a modification from commit 48caf7491595238af2b531026a614221d5d61f38.

Metadata

CVE ID
CVE-2023-26472
State
PUBLISHED
Assigner
GitHub_M
Reserved
2023-02-23 23:22 UTC
Published
2023-03-02 18:25 UTC
Last updated
2025-03-05 20:44 UTC
Primary CWE
CWE-116
CWE-116: Improper Encoding or Escaping of Output
Vendor / Product
xwiki / xwiki-platform
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
xwiki xwiki-platform >= 6.2-milestone-1, < 13.10.10, >= 14.0, < 14.4.6, >= 14.5, < 14.9
Weakness (CWE)
CWESourceDescription
CWE-116 cna CWE-116: Improper Encoding or Escaping of Output
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References (3)
Back to overview