XWiki TextAreaClass Code Injection Vulnerability

Strike ID:
E25-gk3v1
CVSS:
8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2023

Description

This strike exploits a code injection vulnerability in XWiki. The vulnerability exists due to improper validation of user-supplied data in the comment parameter when processing annotations. A remote, authenticated attacker could leverage this flaw to execute arbitrary code on the server with the privileges of the server process.

CVE

References