← Back to browse · API

CVE-2023-29211

Severity
CRITICAL
CVSS
10.0
EPSS
0.01193
Risk score
40.42
CISA KEV
No
PoC
No
Published
2023-04-16
Modified
2025-02-06
First seen
2026-08-07
Aliases
EUVD-2023-1406, GHSA-W7V9-FC49-4QG4
Products
xwiki:xwiki-platform 14.0-rc-1, < 14.4.7, xwiki:xwiki-platform 14.5, < 14.10, xwiki:xwiki-platform 5.3-milestone-2, < 13.10.11
Sources
euvd EUVD-2023-1406

Description

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `wikiId` url parameter. The problem has been patched on XWiki 13.10.11, 14.4.7, and 14.10.

References