Cross-site request forgery in XWiki platform - CVE-2023-37277
Published: July 10, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to cross-site request forgery in the REST API when handling POST requests with form-compatible content types. A remote attacker can cause the victim to submit a crafted request to execute arbitrary code.
User interaction with a user who has programming rights is required for code execution through script macros.