Eval Injection in XWiki platform - CVE-2023-35152
Published: June 20, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in like LiveTableResults when rendering a user's first name field. A remote user can place dangerous content in their first name field to escalate privileges.
The injected content can be executed with programming rights.