XWiki Platform RCE via IconThemeSheet 6.2+ (fixed in 14.9)
CVE-2023-26472 Published on March 2, 2023

XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile
XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even through the user profile for users not having edit right. The issue has been patched in XWiki 14.9, 14.4.6, and 13.10.10. An available workaround is to fix the bug in the page `IconThemesCode.IconThemeSheet` by applying a modification from commit 48caf7491595238af2b531026a614221d5d61f38.

Github Repository NVD

Vulnerability Analysis

CVE-2023-26472 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is an Output Sanitization Vulnerability?

The software prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

CVE-2023-26472 has been classified to as an Output Sanitization vulnerability or weakness.


Products Associated with CVE-2023-26472

Want to know whenever a new CVE is published for Xwiki? stack.watch will email you.

 

Affected Versions

xwiki-platform:

Vulnerable Packages

The following package name and versions may be associated with CVE-2023-26472

Package Manager Vulnerable Package Versions Fixed In
maven org.xwiki.platform:xwiki-platform-icon-ui >= 6.2-milestone-1, < 13.10.10 13.10.10
maven org.xwiki.platform:xwiki-platform-icon-ui >= 14.0, < 14.4.6 14.4.6
maven org.xwiki.platform:xwiki-platform-icon-ui >= 14.5, < 14.9 14.9

Exploit Probability

EPSS
10.31%
Percentile
93.32%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.