{"id":"CVE-2023-45144","aliases":["GHSA-h2rm-29ch-wfmh"],"url":"https://o3.security/vulnerability/CVE-2023-45144","summary":"Remote code execution from login screen through unescaped URL parameter in OAuth Identity XWiki App","details":"### Impact\n\nWhen login via the OAuth method, the identityOAuth parameters, sent in a GET request is vulnerable to XSS and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation. \n\nThe vulnerability is in [this part](https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58) of the code.\n\n### Patches\nThe issue has been fixed in Identity OAuth version 1.6 by https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 . The fix is in the content of the [IdentityOAuth/LoginUIExtension](https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188) file\n\n### Workarounds\nThere are no known workarounds besides upgrading.\n\n### References\n_Are there any links users can visit to find out more?_\n\n* Original report: https://jira.xwiki.org/browse/XWIKI-20719\n","published":"2023-10-16T20:32:50.376Z","modified":"2026-08-12T03:51:46.413562938Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.xwiki.identity-oauth:identity-oauth-ui","fixedVersion":"1.6"}],"fix":{"url":"https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6","label":"xwikisas/identity-oauth@d805d31"},"references":[{"type":"WEB","url":"https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20719"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45144.json"},{"type":"ADVISORY","url":"https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45144"},{"type":"FIX","url":"https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6"},{"type":"FIX","url":"https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188"},{"type":"PACKAGE","url":"https://github.com/xwikisas/identity-oauth"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.413562938Z"}}