CVE-2023-35150: critical vulnerability in xwiki-platform
XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in XWiki's Invitation application allows any user with basic viewing permission to execute code with administrator-level privileges by crafting a malicious URL, potentially taking over the entire system.
CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code) in XWiki's Invitation application permits privilege escalation from view rights to programming rights. An authenticated attacker can craft a specially-formed URL to inject and execute arbitrary code in the context of elevated privileges, achieving remote code execution. Affected versions: 2.40m-2 through 14.4.7, 14.10.3, and versions before 15.0.
In the same product, most dangerous first.