{"id":"CVE-2023-40572","summary":"XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action","details":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/programming right, thus compromising the confidentiality, integrity and availability of the whole XWiki installation. When a user with script right views this image and a log message `ERROR foo - Script executed!` appears in the log, the XWiki installation is vulnerable. This has been patched in XWiki 14.10.9 and 15.4RC1 by requiring a CSRF token for the actual page creation.","aliases":["GHSA-4f8m-7h83-9f6m"],"modified":"2026-08-12T03:51:37.556483706Z","published":"2023-08-24T01:15:33.272Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-352"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40572.json"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20849"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40572.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-4f8m-7h83-9f6m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40572"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/4b20528808d0c311290b0d9ab2cfc44063380ef7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xwiki/xwiki-commons","events":[{"introduced":"0"},{"fixed":"3b0ff213f269a234333b177bfff6d8f227be8256"},{"introduced":"fdba4ca1398766e912f7888af5bdefbeef60d8b0"},{"last_affected":"68863e636fb48bcfc933880f81779d7dd17a06b8"}],"database_specific":{"cpe":["cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","cpe:2.3:a:xwiki:xwiki:15.0:-:*:*:*:*:*:*","cpe:2.3:a:xwiki:xwiki:15.1:-:*:*:*:*:*:*","cpe:2.3:a:xwiki:xwiki:15.2:-:*:*:*:*:*:*","cpe:2.3:a:xwiki:xwiki:15.3:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"14.10.9"},{"introduced":"15.0-NA"},{"last_affected":"15.0-NA"},{"introduced":"15.1-NA"},{"last_affected":"15.1-NA"},{"introduced":"15.2-NA"},{"last_affected":"15.2-NA"},{"introduced":"15.3-NA"},{"last_affected":"15.3-NA"}],"source":["CPE_RANGE","CPE_STRING"]}},{"type":"GIT","repo":"https://github.com/xwiki/xwiki-platform","events":[{"introduced":"817e71d7c385e25600f16c5ed7245eaa20fee43a"},{"fixed":"1b0b53998b15e408df8e3dafd8845896d8d4c50e"},{"introduced":"d823334f762d5ad86bea378b65af0b230668d401"},{"fixed":"68f0a633cd7f031b516940dd9f157b1aec1e1afd"}],"database_specific":{"extracted_events":[{"introduced":"3.2-milestone-3"},{"fixed":"14.10.9"},{"introduced":"15.0-rc-1"},{"fixed":"15.4-rc-1"}],"source":"AFFECTED_FIELD"}}],"versions":["15.0-NA","15.1-NA","15.2-NA","15.3-NA","xwiki-commons-15.3","xwiki-commons-15.3-rc-1","xwiki-commons-14.10.8","xwiki-commons-14.10.7","xwiki-commons-14.10.6","xwiki-commons-14.10.5","xwiki-commons-14.10.4","xwiki-commons-14.10.3","xwiki-commons-14.10.2","xwiki-commons-14.10.1","xwiki-commons-14.10","xwiki-commons-8.3-milestone-2","xwiki-commons-8.3-milestone-1","xwiki-commons-8.2-milestone-2","xwiki-commons-8.2-milestone-1","xwiki-commons-8.1-milestone-2","xwiki-commons-8.1-milestone-1","xwiki-commons-8.0-milestone-2","xwiki-commons-8.0-milestone-1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-40572.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}