HIGH

CVE-2023-29516

CVSS v3

8.8

HIGH

EPSS Score

15.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping in the "Cancel and return to page" button. This page is installed by default. This vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. There are no known workarounds for this vulnerability.

Technical details

Published
4/19/2023

Frequently asked questions

What is CVE-2023-29516?

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping in the "Cancel and return to page" button. This page is installed by default. This vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. There are no known workarounds for this vulnerability.

Is CVE-2023-29516 actively exploited?

Active exploitation of CVE-2023-29516 has not been confirmed. The EPSS score is 15.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-29516?

CVE-2023-29516 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2023-29516 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.