Vulnerability record · CVE-2023-37462 · published 14 July 2023
CVE-2023-37462: XWiki Platform improper escaping in XWikiSkinsSheet enables script injection and RCE
Xwiki · Xwiki
XWiki Platform fails to properly escape content in the document SkinsCode.XWikiSkinsSheet, creating an injection vector that escalates view rights on that document to programming rights. This allows execution of arbitrary script macros, including Groovy and Python, resulting in remote code execution with unrestricted read and write access to all wiki contents. The flaw is triggered by opening a non-existing page whose name is crafted to contain a dangerous payload.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is possible to execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The attack works by opening a non-existing page with a name crafted to contain a dangerous payload. It is possible to check if an existing installation is vulnerable. See the linked GHSA for instructions on testing an installation. This issue has been patched in XWiki 14.4.8, 14.10.4 and 15.0-rc-1. Users are advised to upgrade. The fix commit `d9c88ddc` can also be applied manually to the impacted document `SkinsCode.XWikiSkinsSheet` and users unable to upgrade are advised to manually patch their installations.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high confidentiality, integrity and availability impact plus a very high EPSS score and public exploit references make this a serious risk, though it requires low privileges and is not in KEV.
What it is
XWiki Platform fails to properly escape content in the document SkinsCode.XWikiSkinsSheet, creating an injection vector that escalates view rights on that document to programming rights. This allows execution of arbitrary script macros, including Groovy and Python, resulting in remote code execution with unrestricted read and write access to all wiki contents. The flaw is triggered by opening a non-existing page whose name is crafted to contain a dangerous payload.
Impact
An attacker gains programming rights and can execute arbitrary Groovy or Python macros, leading to remote code execution and full read/write access to all wiki content. This effectively compromises the confidentiality, integrity and availability of the entire wiki instance.
Attack surface
The vector is network-reachable (AV:N) with low attack complexity and no user interaction, but requires low privileges (PR:L), meaning an authenticated user with basic view access can trigger it. The attack is delivered by requesting a non-existing page with a specially crafted name.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high at 0.91592 (99.8th percentile), and multiple references are tagged Exploit, indicating public exploit information exists. No ransomware group usage is documented.
What to do
- Upgrade to XWiki 14.4.8, 14.10.4 or 15.0-rc-1 or later, which contain the fix.
- If upgrading is not possible, manually apply fix commit d9c88ddc to the impacted document SkinsCode.XWikiSkinsSheet.
- Restrict the ability of untrusted users to create or view pages, and review who holds programming rights.
- Monitor for and remove any unexpected pages with crafted names that could carry injection payloads.
- Use the vendor GHSA instructions to check whether an existing installation is vulnerable.
Detection
- Search wiki logs and page creation records for non-existing page requests with unusual or macro-like characters in the page name.
- Monitor for unexpected execution of Groovy or Python macros and for changes to wiki content made by low-privileged accounts.
- Alert on access to SkinsCode.XWikiSkinsSheet by users who do not normally interact with skin documents.
- Review audit logs for privilege escalation to programming rights or unexpected document edits.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/d9c88ddc4c0c78fa534bd33237e95dea66003d29 | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h4vp-69r8-gvjg | ExploitIssue TrackingPatchVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-20457 | ExploitIssue TrackingVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/d9c88ddc4c0c78fa534bd33237e95dea66003d29 | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h4vp-69r8-gvjg | ExploitIssue TrackingPatchVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-20457 | ExploitIssue TrackingVendor Advisory |
Track CVE-2023-37462 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-37462), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.