CVE-2023-50721
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-50721 is a critical vulnerability affecting the XWiki Platform, a generic wiki solution. Starting from version 4.5-rc-1, the search administration interface fails to properly escape the id and label of search user interface extensions. This lack of escaping allows the injection of XWiki syntax containing script macros, including Groovy macros, enabling remote code execution. This vulnerability poses a significant risk to the confidentiality, integrity, and availability of the entire XWiki instance. The issue can be exploited by any user with editing privileges, such as on their profile page, which is set as editable by default. The necessary escaping has been added in XWiki versions 14.10.15, 15.5.2, and 15.7-rc-1. As a temporary measure, the patch can be manually applied to the `XWiki.SearchAdmin` page.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xwiki
Affected Vendors
- xwiki