Eval Injection in XWiki platform - CVE-2023-29516
Published: April 18, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the XWiki.AttachmentSelector page when processing the "Cancel and return to page" button input. A remote user can send a specially crafted value to execute arbitrary code.
This page is installed by default.