CVE-2023-29511: xwiki-platform-administration-ui vulnerable to privilege escalation
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the section ids in XWiki.AdminFieldsDisplaySheet. This page is installed by default. The vulnerability has been patched in XWiki versions 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29511?
CVE-2023-29511 is considered critical due to its potential for remote code execution.
How do I fix CVE-2023-29511?
To fix CVE-2023-29511, update XWiki to a version that has patched the vulnerability.
What types of code can be executed through CVE-2023-29511?
CVE-2023-29511 allows execution of arbitrary Groovy, Python, or Velocity code.
Who is affected by CVE-2023-29511?
Any user with edit rights on a page in XWiki is affected by CVE-2023-29511.
What versions of XWiki are vulnerable to CVE-2023-29511?
CVE-2023-29511 affects XWiki versions from 1.7 to below 14.0 and certain versions up to 14.10.1.