Back to overview

CVE-2023-37912

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and `org.xwiki.platform:xwiki-rendering-macro-footnotes` and prior to version 15.1-rc-1 of `org.xwiki.platform:xwiki-rendering-macro-footnotes`, the footnote macro executed its content in a potentially different context than the one in which it was defined. In particular in combination with the include macro, this allows privilege escalation from a simple user account in XWiki to programming rights and thus remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.6 and 15.1-rc-1. There is no workaround apart from upgrading to a fixed version of the footnote macro.

Metadata

CVE ID
CVE-2023-37912
State
PUBLISHED
Assigner
GitHub_M
Reserved
2023-07-10 17:51 UTC
Published
2023-10-25 17:33 UTC
Last updated
2024-09-12 20:47 UTC
Primary CWE
CWE-270
CWE-270: Privilege Context Switching Error
Vendor / Product
xwiki / xwiki-rendering
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
xwiki xwiki-rendering < 14.10.6, >= 15.0-rc-1, < 15.1-rc-1
Weakness (CWE)
CWESourceDescription
CWE-270 cna CWE-270: Privilege Context Switching Error
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References (3)
Back to overview