Vulnerability Description
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping in the code for displaying sections in the administration interface. This impacts the confidentiality, integrity and availability of the whole XWiki installation. Normally, all users are allowed to edit their own user profile so this should be exploitable by all users of the XWiki instance. This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1. The patches can be manually applied to the `XWiki.ConfigurableClassMacros` and `XWiki.ConfigurableClass` pages.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Xwiki | >= 2.3, < 14.10.5 |
Related Weaknesses (CWE)
References
- https://github.com/xwiki/xwiki-platform/commit/0f367aaae4e0696f61cf5a67a75edd27dPatch
- https://github.com/xwiki/xwiki-platform/commit/1157c1ecea395aac7f64cd8a6f484b122Patch
- https://github.com/xwiki/xwiki-platform/commit/749f6aee1bfbcf191c3734ea0aa9eba3aPatch
- https://github.com/xwiki/xwiki-platform/commit/bd82be936c21b65dee367d558e3050b9bPatch
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-qj86-p74r-7wp5PatchVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-21121PatchVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-21122PatchVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-21194PatchVendor Advisory
- https://github.com/xwiki/xwiki-platform/commit/0f367aaae4e0696f61cf5a67a75edd27dPatch
- https://github.com/xwiki/xwiki-platform/commit/1157c1ecea395aac7f64cd8a6f484b122Patch
- https://github.com/xwiki/xwiki-platform/commit/749f6aee1bfbcf191c3734ea0aa9eba3aPatch
- https://github.com/xwiki/xwiki-platform/commit/bd82be936c21b65dee367d558e3050b9bPatch
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-qj86-p74r-7wp5PatchVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-21121PatchVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-21122PatchVendor Advisory
FAQ
What is CVE-2023-50723?
CVE-2023-50723 is a vulnerability with a CVSS score of 9.9 (CRITICAL). XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programmi...
How severe is CVE-2023-50723?
CVE-2023-50723 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-50723?
Check the references section above for vendor advisories and patch information. Affected products include: Xwiki Xwiki.