XML External Entity injection in XWiki platform - CVE-2023-27480
Published: March 7, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper restriction of XML external entity reference in the XAR import package.xml parser when parsing a forged XAR file during import. A remote user can upload a specially crafted XAR file and trigger its import to disclose sensitive information.
Exploitation requires edit rights on a document and can expose the content of files on the XWiki server host.