Critical severity9.9NVD Advisory· Published Jun 23, 2023· Updated Jun 17, 2026
CVE-2023-35152
CVE-2023-35152
Description
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their first name field and see it executed with programming rights. Leading to rights escalation. The vulnerability has been fixed on XWiki 14.4.8, 14.10.6, and 15.1. As a workaround, one may apply the patch manually.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.xwiki.platform:xwiki-platform-like-uiMaven | >= 12.9-rc-1, < 14.4.8 | 14.4.8 |
org.xwiki.platform:xwiki-platform-like-uiMaven | >= 14.5, < 14.10.6 | 14.10.6 |
org.xwiki.platform:xwiki-platform-like-uiMaven | >= 15.0-rc-1, < 15.1 | 15.1 |
Affected products
6- Range: >= 12.9-rc-1, < 14.4.8
Patches
Vulnerability mechanics
References
7- github.com/xwiki/xwiki-platform/commit/0993a7ab3c102f9ac37ffe361a83a3dc302c0e45nvdPatchVendor AdvisoryWEB
- github.com/xwiki/xwiki-platform/commit/6ce2d04a5779e07f6d3ed3f37d4761049b4fc3acnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-rf8j-q39g-7xfmghsaADVISORY
- github.com/xwiki/xwiki-platform/security/advisories/GHSA-rf8j-q39g-7xfmnvdVendor AdvisoryWEB
- jira.xwiki.org/browse/XWIKI-19900nvdIssue TrackingVendor AdvisoryWEB
- jira.xwiki.org/browse/XWIKI-20611nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-35152ghsaADVISORY
News mentions
0No linked articles in our index yet.