Eval Injection in XWiki platform - CVE-2023-29519

 

Eval Injection in XWiki platform - CVE-2023-29519

Published: April 18, 2023 / Updated: May 5, 2026


Vulnerability identifier: #VU129966
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29519
CWE-ID: CWE-95
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the attachment selector when processing the "property" field of an attachment selector as a gadget of the attacker's own dashboard. A remote attacker can inject crafted code in the "property" field to execute arbitrary code.

The issue can lead to privilege escalation. Comments of a wiki are not affected.


Affected software

XWiki platform

How to mitigate CVE-2023-29519

Install security update from vendor's website.

XWiki platform - addressed in versions 13.10.11, 14.4.8, 14.10.2

External References

Related Security Bulletins