Eval Injection in XWiki platform - CVE-2022-36100

 

Eval Injection in XWiki platform - CVE-2022-36100

Published: September 8, 2022 / Updated: May 5, 2026


Vulnerability identifier: #VU130008
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36100
CWE-ID: CWE-95
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code with programming rights.

The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the Main.Tags document when handling the do=viewTag request with a user-supplied tag parameter. A remote user can send a specially crafted request to execute arbitrary code with programming rights.

On public wikis, view rights on the document are granted by default, and on private wikis authenticated users typically have the required view rights. On versions before 13.10.4 and 14.2, the issue can be chained with an authentication bypass in the login action so that no rights are required.


Affected software

XWiki platform

How to mitigate CVE-2022-36100

Install security update from vendor's website.

XWiki platform - addressed in versions 13.10.6, 14.4

External References

Related Security Bulletins