Missing Authorization in XWiki platform - CVE-2023-37910
Published: October 25, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and modify attachments.
The vulnerability exists due to missing authorization in attachment move support in org.xwiki.platform:xwiki-platform-attachment-api when moving attachments between documents. A remote user can move an attachment from another document to an attacker-controlled document to disclose sensitive information and modify attachments.
The source attachment name must be known, and the moved attachment is deleted from the source document.