CVE-2023-46731 is a critical code injection vulnerability affecting XWiki Platform versions prior to 14.10.14, 15.6 RC1, and 15.5.1. It allows unauthenticated attackers with read access to the XWiki.AdminSheet document to execute arbitrary code, including Groovy, due to improper escaping of the section URL parameter. This flaw carries a CVSS score of 9.8 (Critical) and can lead to complete compromise of confidentiality, integrity, and availability of the XWiki instance, requiring no user interaction or complex attack steps. While there is no evidence of active exploitation (KEV list), the vulnerability has a high EPSS score, a FAUCET Risk Score of 98/100, and significant community discussion, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.10.14CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.5.1CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.