Improper Encoding or Escaping of Output in XWiki platform - CVE-2023-29525
Published: April 18, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper encoding or escaping of output in XWiki.Notifications.Code.LegacyNotificationAdministration when handling the since parameter. A remote user can send a specially crafted request to escalate privileges.
The issue allows privilege escalation from view right to programming rights through XWiki syntax injection.