Improper privilege management in XWiki platform - CVE-2022-23616
Published: February 9, 2022 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper privilege management in the Reset password feature when saving a user profile containing an injected groovy script. A remote user can inject a groovy script into their own profile and invoke the Reset password feature to execute arbitrary code.