Eval Injection in XWiki platform - CVE-2023-29523
Published: April 18, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the display method used in user profiles when rendering a document field with wiki syntax. A remote user can edit their own user profile to execute arbitrary code.
The issue can also be exploited in other contexts where the display method on a document is used to display a field with wiki syntax, including applications created using App Within Minutes.