CVE-2023-32069

Source
https://cve.org/CVERecord?id=CVE-2023-32069
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-32069.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-32069
Aliases
Published
2023-05-09T15:31:59.892Z
Modified
2026-05-15T04:06:54.156727280Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
XWiki Platform privilege escalation (PR)/RCE from account through class sheet
Details

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This has been patched in XWiki 15.0-rc-1 and 14.10.4. There are no known workarounds.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32069.json"
}
References

Affected packages