Eval Injection in XWiki platform - CVE-2023-29516

 

Eval Injection in XWiki platform - CVE-2023-29516

Published: April 18, 2023 / Updated: May 5, 2026


Vulnerability identifier: #VU129968
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29516
CWE-ID: CWE-95
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the XWiki.AttachmentSelector page when processing the "Cancel and return to page" button input. A remote user can send a specially crafted value to execute arbitrary code.

This page is installed by default.


Affected software

XWiki platform

How to mitigate CVE-2023-29516

Install security update from vendor's website.

XWiki platform - addressed in versions 13.10.11, 14.4.8, 14.10.1, 15.0

External References

Related Security Bulletins