Vulnerability record · CVE-2023-29525 · published 19 April 2023
CVE-2023-29525: XWiki Platform code injection in Notifications since parameter
Xwiki · Xwiki
XWiki Platform fails to escape the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint, allowing XWiki syntax injection. An authenticated user with only view rights can inject syntax that escalates to programming rights and then execute code. The flaw is patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8 and 14.10.3.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint. This provides an XWiki syntax injection attack via the since-parameter, allowing privilege escalation from view to programming rights and subsequent code execution privilege. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8 and 14.10.3. Users are advised to upgrade. Users unable to upgrade may modify the page `XWiki.Notifications.Code.LegacyNotificationAdministration` to add the missing escaping. For versions < 14.6-rc-1 a workaround is to modify the file `<xwikiwebapp>/templates/distribution/eventmigration.wiki` to add the missing escaping.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low-privileged authenticated network access and public exploit references, though not in KEV.
What it is
XWiki Platform fails to escape the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint, allowing XWiki syntax injection. An authenticated user with only view rights can inject syntax that escalates to programming rights and then execute code. The flaw is patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8 and 14.10.3.
Impact
An attacker gains privilege escalation from view to programming rights and can execute arbitrary code on the XWiki server. This effectively gives full control over the application and its host.
Attack surface
Reached over the network via the LegacyNotificationAdministration endpoint with the `since` parameter. The CVSS vector shows PR:L, so a low-privileged authenticated account is required; no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.77752 (99.5th percentile) and the vendor advisory and Jira references are tagged Exploit, indicating public exploit information exists.
What to do
- Upgrade to XWiki 15.0-rc-1, 14.10.3, 14.4.8 or later.
- If upgrade is not possible, modify the page `XWiki.Notifications.Code.LegacyNotificationAdministration` to add the missing escaping.
- For versions before 14.6-rc-1, modify `<xwikiwebapp>/templates/distribution/eventmigration.wiki` to add the missing escaping.
- Restrict access to the LegacyNotificationAdministration endpoint and review accounts with view rights.
Detection
- Monitor requests to `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` for unusual or encoded `since` parameter values.
- Alert on XWiki syntax or scripting tokens appearing in the `since` parameter.
- Audit XWiki logs for privilege changes to programming rights or unexpected code execution following notification administration requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/6d74e2e4aa03d19f0be385ab63ae9e0f0e90a766 | Patch |
| https://github.com/xwiki/xwiki-platform/commit/8e7c7f90f2ddaf067cb5b83b181af41513028754#diff-4e13f4ee4a42938bf1201b7ee71 | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jgg7-w2rj-58cj | ExploitPatchVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-20287 | ExploitIssue TrackingPatchVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/6d74e2e4aa03d19f0be385ab63ae9e0f0e90a766 | Patch |
| https://github.com/xwiki/xwiki-platform/commit/8e7c7f90f2ddaf067cb5b83b181af41513028754#diff-4e13f4ee4a42938bf1201b7ee71 | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jgg7-w2rj-58cj | ExploitPatchVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-20287 | ExploitIssue TrackingPatchVendor Advisory |
Track CVE-2023-29525 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-29525), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.