← Back to browse · API

CVE-2023-45144

Severity
CRITICAL
CVSS
10.0
EPSS
0.01088
Risk score
40.38
CISA KEV
No
PoC
No
Published
2023-10-16
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2023-2744, GHSA-H2RM-29CH-WFMH
Products
xwikisas:identity-oauth 1.0, < 1.6
Sources
euvd EUVD-2023-2744

Description

com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation. The issue has been fixed in Identity OAuth version 1.6. There are no known workarounds for this vulnerability and users are advised to upgrade.

References