Incorrect authorization in XWiki platform - CVE-2023-46244
Published: November 7, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to incorrect authorization in the title displayer API when executing velocity content in a script. A remote privileged user can create a document containing specially crafted velocity code to escalate privileges.
The issue allows velocity content to be executed with the rights of another document's content author.