CVE-2023-26477: critical vulnerability in xwiki-platform
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A vulnerability in XWiki allows attackers to inject and execute arbitrary code (Groovy, Python, Velocity scripts) through a URL parameter called 'newThemeName' when changing themes. This can completely compromise the wiki and any system it runs on.
CWE-95 Code Injection via the 'newThemeName' URL parameter enables unauthenticated remote code execution through wiki syntax macro injection (Groovy, Python, Velocity). Exploitation requires crafting malicious URL parameters; no authentication or special conditions are needed. Impact is critical as arbitrary code execution allows complete system compromise.
In the same product, most dangerous first.