← Back to browse · API

CVE-2023-30537

Severity
CRITICAL
CVSS
9.9
EPSS
0.01037
Risk score
39.96
CISA KEV
No
PoC
No
Published
2023-04-16
Modified
2025-02-06
First seen
2026-08-07
Aliases
EUVD-2023-1398, GHSA-VRR8-FP7C-7QGP
Products
xwiki:xwiki-platform 12.6.6, < 13.10.11, xwiki:xwiki-platform 14.0-rc-1, < 14.4.7, xwiki:xwiki-platform 14.5, < 14.10
Sources
euvd EUVD-2023-1398

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the styles properties `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki versions 13.10.11, 14.4.7 and 14.10.

References