{"id":"CVE-2023-35150","aliases":["GHSA-6mf5-36v9-3h2w"],"url":"https://o3.security/vulnerability/CVE-2023-35150","summary":"XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application","details":"### Impact\nAny user with view rights on any document can execute code with programming rights, leading to remote code execution by crafting an url with a dangerous payload. See the example below:\nOpen `<xwiki-host>/xwiki/bin/view/%5D%5D%20%7B%7Basync%20async%3D%22true%22%20cached%3D%22false%22%20context%3D%22doc.reference%22%7D%7D%7B%7Bgroovy%7D%7Dprintln(%22Hello%20%22%20%2B%20%22from%20groovy!%22)%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D?sheet=Invitation.InvitationGuestActions&xpage=view` where `<xwiki-host>` is the URL of your XWiki installation.\n\n### Patches\nThe problem as been patching on XWiki 15.0, 14.10.4 and 14.4.8.\n\n### Workarounds\nIt is possible to partially fix the issue by applying this [patch](https://github.com/xwiki/xwiki-platform/commit/b65220a4d86b8888791c3b643074ebca5c089a3a). Note that some additional issue can remain and can be fixed automatically by a migration. Hence, it is advised to upgrade to one of the patched version instead of patching manually.\n\n### References\n- https://jira.xwiki.org/browse/XWIKI-20285\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n*    Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n*    Email us at [Security Mailing List](mailto:security@xwiki.org)","published":"2023-06-23T16:26:55.213Z","modified":"2026-08-12T03:51:43.618606521Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"},"epss":{"score":0.77654,"percentile":0.99528,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-invitation-ui","fixedVersion":"14.4.8"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-invitation-ui","fixedVersion":"14.10.4"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-invitation-ui","fixedVersion":"15.0"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/b65220a4d86b8888791c3b643074ebca5c089a3a","label":"xwiki/xwiki-platform@b65220a"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20285"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35150.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-6mf5-36v9-3h2w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-35150"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/b65220a4d86b8888791c3b643074ebca5c089a3a"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.618606521Z"}}