CVE-2023-35150 identifies a critical arbitrary code injection vulnerability in XWiki Platform versions prior to 14.4.8, 14.10.4, and 15.0. This flaw allows any authenticated user with view rights on a document to achieve remote code execution by crafting a malicious URL. Rated with a CVSS score of 8.0 (High), the vulnerability has a network attack vector and low attack complexity, requiring only low privileges and user interaction to achieve high confidentiality, integrity, and availability impacts. Although not yet on CISA's KEV catalog, it is on the "Hot List" and has generated significant community discussion and detailed analysis by security researchers, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5, < 14.4.8CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 14.10, < 14.10.4CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:2.4:milestone2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.