Improper Encoding or Escaping of Output in XWiki platform - CVE-2023-29524
Published: April 18, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to execute arbitrary code with elevated privileges.
The vulnerability exists due to improper encoding or escaping of output in XWiki.SchedulerJobSheet when rendering a user profile containing a crafted XWiki.SchedulerJobClass object. A remote user can add a malicious job script to their profile and access the scheduler job sheet to execute arbitrary code with elevated privileges.
The issue can be triggered by a user without script or programming rights.