CVE-2023-26471

high-risk
Published 2023-03-02

XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means that any user with comment right can use the async macro to make it execute any wiki content with the right of superadmin. This has been patched in XWiki 14.9, 14.4.6, and 13.10.10. The only known workaround consists of applying a patch and rebuilding and redeploying `org.xwiki.platform:xwiki-platform-rendering-async-macro`.

Do I need to act?

!
11.0% chance of exploitation in next 30 days
EPSS score — higher than 89% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 61a67f5cf241df692779d77367168e0762119091, 4db5104960c1c13a7d2b740800e2b9d0091444d8, 101becab4069ae9ccdc8c2f2c4edc562645e152b
9
CVSS 9.9/10 Critical
NETWORK / LOW complexity

Affected Products (2)

Affected Vendors

51
/ 100
high-risk
Severity 33/34 · Critical
Exploitability 11/34 · Low
Exposure 7/34 · Low