CVE-2023-29525: Privilege escalation from view right on XWiki.Notifications.Code.LegacyNotificationAdministration in xwiki-platform

Published Apr 18, 2023
·
Updated

Impact

Steps to reproduce:

Open <xwiki-host>/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration?since=%7B%7B%2Fhtml%7D%7D+%7B%7Basync+async%3D%22true%22+cached%3D%22false%22+context%3D%22doc.reference%22%7D%7D%7B%7Bgroovy%7D%7Dprintln%28%22Hello+%22+%2B+%22from+groovy%21%22%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D, where <xwiki-host> is the URL of your XWiki installation.

This demonstrates an XWiki syntax injection attack via the since-parameter, allowing privilege escalation from view to programming rights.

Patches

The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8 and 14.10.3.

Workarounds

For versions >= 14.6-rc-1 the workaround is to modify the page XWiki.Notifications.Code.LegacyNotificationAdministration to add the missing escaping, as described on https://github.com/xwiki/xwiki-platform/commit/8e7c7f90f2ddaf067cb5b83b181af41513028754#diff-4e13f4ee4a42938bf1201b7ee71ca32edeacba22559daf0bcb89d534e0225949R70

For versions < 14.6-rc-1 the workaround is to modify the file <xwikiwebapp>/templates/distribution/eventmigration.wiki to add the missing escaping, as described on https://github.com/xwiki/xwiki-platform/commit/6d74e2e4aa03d19f0be385ab63ae9e0f0e90a766

References

https://jira.xwiki.org/browse/XWIKI-20287

For more information

If you have any questions or comments about this advisory: Open an issue in Jira XWiki.org Email us at Security Mailing List

Other sources

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the since parameter of the /xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration endpoint. This provides an XWiki syntax injection attack via the since-parameter, allowing privilege escalation from view to programming rights and subsequent code execution privilege. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8 and 14.10.3. Users are advised to upgrade. Users unable to upgrade may modify the page XWiki.Notifications.Code.LegacyNotificationAdministration to add the missing escaping. For versions < 14.6-rc-1 a workaround is to modify the file <xwikiwebapp>/templates/distribution/eventmigration.wiki to add the missing escaping.

Affected Software

6 affected componentsFixes available
maven/org.xwiki.platform:xwiki-platform-legacy-events-hibernate-ui>=14.6-rc-1<14.10.3
14.10.3
maven/org.xwiki.platform:xwiki-platform-distribution-war>=14.5<14.6-rc-1
14.6-rc-1
maven/org.xwiki.platform:xwiki-platform-distribution-war>=14.0-rc-1<14.4.8
14.4.8
maven/org.xwiki.platform:xwiki-platform-distribution-war>=12.6.1<13.10.11
13.10.11
XWiki xwiki<14.4.8
XWiki xwiki>=14.5<14.10.3

Event History

Apr 18, 2023
CVE Published
via MITRE·11:01 PM
Data Sourced
via MITRE·11:01 PM
DescriptionSeverityWeakness
Apr 20, 2023
Advisory Published
10:25 PM

Frequently Asked Questions

1

What is the vulnerability ID for this issue?

The vulnerability ID for this issue is CVE-2023-29525.

2

What is the severity of CVE-2023-29525?

The severity of CVE-2023-29525 is critical, with a severity value of 8.8.

3

What software versions are affected by CVE-2023-29525?

Versions up to and excluding 14.4.8 of XWiki and versions between 14.5 and 14.10.3 of XWiki are affected by CVE-2023-29525.

4

How does CVE-2023-29525 impact XWiki?

CVE-2023-29525 allows code injection in the 'since' parameter of the '/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration' endpoint in XWiki.

5

How can I fix CVE-2023-29525?

To fix CVE-2023-29525, update XWiki to a version that is not affected by the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203