CVE-2023-37462 is a critical improper escaping vulnerability in the XWiki Platform, specifically within the SkinsCode.XWikiSkinsSheet document. This flaw allows an attacker with view rights to achieve programming rights and execute arbitrary script macros, including Groovy and Python, leading to remote code execution and unrestricted access to wiki contents. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, the vulnerability poses a significant risk due to its low attack complexity and severe impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, a Nuclei template for exploitation exists, and users are strongly advised to upgrade to patched versions (XWiki 14.4.8, 14.10.4, 15.0-rc-1) or manually apply the provided fix.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, < 14.4.8CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 14.5, < 14.10.4CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.