{"id":"CVE-2023-37912","aliases":["GHSA-35j5-m29r-xfq5"],"url":"https://o3.security/vulnerability/CVE-2023-37912","summary":"XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro","details":"### Impact\n\nThe footnote macro executed its content in a potentially different context than the one in which it was defined. In particular in combination with the include macro, this allows privilege escalation from a simple user account in XWiki to programming rights and thus remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki installation.\n\nTo reproduce, perform the following steps:\n\n1. Edit your user profile with the object editor and add an object of type DocumentSheetBinding with value XWiki.ClassSheet\n2. Edit your user profile with the wiki editor and add the syntax `{{footnote}}{{groovy}}println(\"Hello \" + \"from groovy!\"){{/groovy}}{{/footnote}}`\n\nWhen the text \"Hello from groovy!\" is displayed at the bottom of the document, the installation is vulnerable. Instead, an error should be displayed.\n\n### Patches\nThis vulnerability has been patched in XWiki 14.10.6 and 15.1-rc-1.\n\n### Workarounds\nThere is no workaround apart from upgrading to a fixed version of the footnote macro.\n\n### References\n* https://jira.xwiki.org/browse/XRENDERING-688\n* https://github.com/xwiki/xwiki-rendering/commit/5f558b8fac8b716d19999225f38cb8ed0814116e\n","published":"2023-10-25T17:33:54.756Z","modified":"2026-08-12T13:32:39.034157Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.rendering:xwiki-rendering-macro-footnotes","fixedVersion":"14.10.6"},{"ecosystem":"Maven","name":"org.xwiki.rendering:xwiki-rendering-macro-footnotes","fixedVersion":"15.1-rc-1"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-core-rendering-macro-footnotes","fixedVersion":"14.10.6"}],"fix":{"url":"https://github.com/xwiki/xwiki-rendering/commit/5f558b8fac8b716d19999225f38cb8ed0814116e","label":"xwiki/xwiki-rendering@5f558b8"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XRENDERING-688"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37912.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-35j5-m29r-xfq5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37912"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-rendering/commit/5f558b8fac8b716d19999225f38cb8ed0814116e"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-rendering"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:32:39.034157Z"}}