Loading HuntDB...

GHSA-w7v9-fc49-4qg4

GitHub Security Advisory

org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

### Impact
Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `wikiId` url parameter.

A proof of concept exploit is to open <xwiki-host>/xwiki/bin/view/WikiManager/DeleteWiki?wikiId=%22+%2F%7D%7D+%7B%7Basync+async%3D%22true%22+cached%3D%22false%22+context%3D%22doc.reference%22%7D%7D%7B%7Bgroovy%7D%7Dprintln%28%22Hello+from+groovy%21%22%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D where <xwiki-host> is the URL of your XWiki installation.

### Patches
The problem has been patched on XWiki 13.10.11, 14.4.7, and 14.10.

### Workarounds
The issue can be fixed manually applying this [patch](https://github.com/xwiki/xwiki-platform/commit/ba4c76265b0b8a5e2218be400d18f08393fe1428#diff-64f39f5f2cc8c6560a44e21a5cfd509ef00e8a2157cd9847c9940a2e08ea43d1R63-R64).

If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:[email protected])

Affected Packages

Maven org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
Affected versions: 5.3-milestone-2 (fixed in 13.10.11)
Maven org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
Affected versions: 14.0-rc-1 (fixed in 14.4.7)
Maven org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
Affected versions: 14.5 (fixed in 14.10)

Related CVEs

Key Information

GHSA ID
GHSA-w7v9-fc49-4qg4
Published
April 12, 2023 8:35 PM
Last Modified
April 26, 2023 8:33 PM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 22, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.