CVE-2023-50721

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Dec 15, 2023
Updated: Dec 19, 2023
CWE ID 94
CWE ID 95

Summary

CVE-2023-50721 is a critical vulnerability affecting the XWiki Platform, a generic wiki solution. Starting from version 4.5-rc-1, the search administration interface fails to properly escape the id and label of search user interface extensions. This lack of escaping allows the injection of XWiki syntax containing script macros, including Groovy macros, enabling remote code execution. This vulnerability poses a significant risk to the confidentiality, integrity, and availability of the entire XWiki instance. The issue can be exploited by any user with editing privileges, such as on their profile page, which is set as editable by default. The necessary escaping has been added in XWiki versions 14.10.15, 15.5.2, and 15.7-rc-1. As a temporary measure, the patch can be manually applied to the `XWiki.SearchAdmin` page.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share