Loading HuntDB...

GHSA-h63h-5c77-77p5

GitHub Security Advisory

XWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheet

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

### Impact
Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchSuggestSourceClass` to their user profile or any other page. This compromises the confidentiality, integrity and availability of the whole XWiki installation.

To reproduce on an instance, as a user without script nor programming rights, add an object of type `XWiki.SearchSuggestConfig` to your profile page, and an object of type `XWiki.SearchSuggestSourceClass` as well. On this last object, set both `name` and `icon` properties to `$services.logging.getLogger("attacker").error("I got programming: $services.security.authorization.hasAccess('programming')")` and `limit` and `engine` to `{{/html}}{{async}}{{velocity}}$services.logging.getLogger("attacker").error("I got programming: $services.security.authorization.hasAccess('programming')"){{/velocity}}{{/async}}`. Save and display the page. If the logs contain any message `ERROR attacker - I got programming: true` then the instance is vulnerable.

### Patches
This vulnerability has been patched in XWiki 14.10.21, 15.5.5 and 15.10.2.

### Workarounds
We're not aware of any workaround except upgrading.

### References
- https://jira.xwiki.org/browse/XWIKI-21473
- https://github.com/xwiki/xwiki-platform/commit/742cd4591642be4cdcaf68325f17540e0934e64e

Affected Packages

Maven org.xwiki.platform:xwiki-platform-search-ui
Affected versions: 9.2-rc-1 (fixed in 14.10.21)
Maven org.xwiki.platform:xwiki-platform-search-ui
Affected versions: 15.0-rc-1 (fixed in 15.5.5)
Maven org.xwiki.platform:xwiki-platform-search-ui
Affected versions: 15.6-rc-1 (fixed in 15.10.2)

Related CVEs

Key Information

GHSA ID
GHSA-h63h-5c77-77p5
Published
July 31, 2024 3:24 PM
Last Modified
September 6, 2024 9:41 PM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
org.xwiki.platform:xwiki-platform-search-ui
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.