Incorrect authorization in XWiki platform - CVE-2023-35166
Published: June 20, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary wiki content with the rights of the TipsPanel author.
The vulnerability exists due to incorrect authorization in the TipsPanel UI extension handling when processing a crafted tip UI extension. A remote user can create a tip UI extension for the org.xwiki.platform.help.tipsPanel extension point to execute arbitrary wiki content with the rights of the TipsPanel author.