Vulnerability record · CVE-2023-35150 · published 23 June 2023
CVE-2023-35150: XWiki Platform code injection lets any viewer execute code with programming rights
Xwiki · Xwiki
XWiki Platform fails to properly restrict code execution, so any user with view rights on a document can execute code with programming rights by crafting a URL containing a dangerous payload. This turns a low-privileged wiki account into remote code execution on the server. Patches exist in XWiki 15.0, 14.10.4 and 14.4.8.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to remote code execution by crafting an url with a dangerous payload. The problem has been patched in XWiki 15.0, 14.10.4 and 14.4.8.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution reachable by any user with view rights, with a patch available and very high EPSS, though not in KEV.
What it is
XWiki Platform fails to properly restrict code execution, so any user with view rights on a document can execute code with programming rights by crafting a URL containing a dangerous payload. This turns a low-privileged wiki account into remote code execution on the server. Patches exist in XWiki 15.0, 14.10.4 and 14.4.8.
Impact
An attacker gains remote code execution with the privileges of the XWiki server process, allowing full compromise of the wiki host and any data or credentials it can reach.
Attack surface
Reachable over the network via a crafted URL; the attacker needs an account with view rights on at least one document, and the CVSS vector indicates user interaction is required. No elevated privileges are needed beyond basic view access.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.776, 99.5th percentile) and a vendor JIRA reference is tagged Exploit, indicating public exploit detail is available. No ransomware usage is documented.
What to do
- Upgrade to XWiki 15.0, 14.10.4 or 14.4.8 (or later) immediately.
- If patching is delayed, restrict view rights and anonymous access so untrusted users cannot reach documents.
- Review and remove unnecessary programming rights from documents and authors.
- Monitor XWiki logs and web traffic for crafted URLs containing code payloads.
- Apply network controls to limit outbound and lateral movement from the XWiki host.
Detection
- Search web/proxy logs for XWiki requests with encoded or script-like payloads in URL parameters.
- Alert on XWiki processes spawning unexpected child processes or shells.
- Audit XWiki documents and revisions for newly added code using programming rights.
- Monitor for unusual outbound connections from the XWiki server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/b65220a4d86b8888791c3b643074ebca5c089a3a | PatchVendor Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-6mf5-36v9-3h2w | Vendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-20285 | ExploitIssue TrackingPatchVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/b65220a4d86b8888791c3b643074ebca5c089a3a | PatchVendor Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-6mf5-36v9-3h2w | Vendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-20285 | ExploitIssue TrackingPatchVendor Advisory |
Track CVE-2023-35150 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-35150), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.