Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.124364
Category:Web application abuses
Title:XWiki 7.4.4 < 14.10.3 Code Injection Vulnerability (GHSA-jgrg-qvpp-9vwr)
Summary:Xwiki is prone to a code injection vulnerability.
Description:Summary:
Xwiki is prone to a code injection vulnerability.

Vulnerability Insight:
In affected versions a user without script or programming right
may edit a user profile (or any other document) with the wiki editor and add groovy script
content. Viewing the document after saving it will execute the groovy script in the server
context which provides code execution.

Affected Software/OS:
XWiki version 7.4.4 prior to 14.10.3.

Solution:
Update to version 14.10.3 or later.

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-29527
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jgrg-qvpp-9vwr
https://jira.xwiki.org/browse/XWIKI-20423
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.