{"id":"CVE-2023-45138","aliases":["GHSA-f776-w9v2-7vfj"],"url":"https://o3.security/vulnerability/CVE-2023-45138","summary":"Change Request Application vulnerable to XSS and remote code execution through change request title","details":"### Impact\n\nIt's possible for a user without any specific right to perform script injection and remote code execution just by inserting an appropriate title when creating a new Change Request. \nThis vulnerability is particularly critical as Change Request aims at being created by user without any particular rights.\n\n### Patches\n\nThe vulnerability has been fixed in Change Request 1.9.2. \n\n### Workarounds\n\nIt's possible to workaround the issue without upgrading by editing the document `ChangeRequest.Code.ChangeRequestSheet` and by performing the same change as in the commit: https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4. \n\n### References\n\n  * JIRA ticket: https://jira.xwiki.org/browse/CRAPP-298\n  * Commit of the fix: https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nThanks Michael Hamann for the report.","published":"2023-10-12T16:22:10.459Z","modified":"2026-08-12T03:51:17.851245642Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.71159,"percentile":0.99378,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.contrib.changerequest:application-changerequest-ui","fixedVersion":"1.9.2"}],"fix":{"url":"https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4","label":"xwiki-contrib/application-changerequest@7565e72"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/CRAPP-298"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45138.json"},{"type":"ADVISORY","url":"https://github.com/xwiki-contrib/application-changerequest/security/advisories/GHSA-f776-w9v2-7vfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45138"},{"type":"FIX","url":"https://github.com/xwiki-contrib/application-changerequest/commit/7565e720117f73102f5a276239eabfe85e15cff4"},{"type":"PACKAGE","url":"https://github.com/xwiki-contrib/application-changerequest"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:17.851245642Z"}}