Code Injection in XWiki platform - CVE-2023-45135
Published: October 25, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of script in the page creation action when processing a user-supplied title parameter during page creation. A remote user can send a crafted link and trick the victim into clicking the "Create" button to execute arbitrary code.
User interaction is required, and the impact depends on the rights of the victim, including script execution with script right or full instance access with programming right.