CVE-2023-46243 is a critical vulnerability affecting XWiki Platform versions prior to 14.10.6 and 15.2RC1, allowing authenticated users with edit rights to execute arbitrary Groovy code on the server. This remote code execution flaw carries a CVSSv3.1 score of 8.8 (High), indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While there are no known active exploits, public exploit code, or significant community discussion, the high EPSS score suggests a notable probability of future exploitation. Organizations are strongly advised to update to patched versions as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0, < 14.10.6CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.2CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.