CRITICAL🇵🇱 Wersja polska

CVE-2023-37912

CVSS 9.9v3.1pub. 2023-10-25upd. 2024-11-21

XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and `org.xwiki.platform:xwiki-rendering-macro-footnotes` and prior to version 15.1-rc-1 of `org.xwiki.platform:xwiki-rendering-macro-footnotes`, the footnote macro executed its content in a potentially different context than the one in which it was defined. In particular in combination with the include macro, this allows privilege escalation from a simple user account in XWiki to programming rights and thus remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.6 and 15.1-rc-1. There is no workaround apart from upgrading to a fixed version of the footnote macro.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Xwiki Rendering

    APP
    Xwiki
    15.0< 14.10.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
CWE
References

Related vulnerabilities

CVE-2023-37908CRITICAL9.0PL ✓same product

XWiki Rendering — XSS via nieprawidłowe atrybuty XHTML umożliwiający RCE

CVE-2025-66474HIGH8.7same product

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML...

CVE-2026-24128MEDIUM6.5same product

XWiki Platform to ogólna platforma wiki oferująca usługi wykonawcze dla aplikacji na niej zbudowanych. Wersje ...

CVE-2025-24893CRITICAL9.8⚠ KEVPL ✓same vendor

XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch

CVE-2025-65091CRITICAL10.0PL ✓same vendor

SQL Injection w XWiki Full Calendar Macro — dostęp bez uwierzytelnienia