{"id":"CVE-2023-50732","summary":"Velocity execution without script right through tree macro","details":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.","aliases":["GHSA-p5f8-qf24-24cj"],"modified":"2026-08-12T03:51:35.886715751Z","published":"2023-12-21T19:42:01.215Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50732.json"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20625"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50732.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-p5f8-qf24-24cj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50732"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/41d7dca2d30084966ca6a7ee537f39ee8354a7e3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xwiki/xwiki-commons","events":[{"introduced":"d9f3a2169df747a805dba03b1170407410840501"},{"fixed":"1e168fcaa5e247cbb1c03ee66e5cffbcd36e3d71"},{"introduced":"fdba4ca1398766e912f7888af5bdefbeef60d8b0"},{"fixed":"16d8434e51afd80d6f06568c8449eb0c9fbfdb40"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.3"},{"fixed":"14.10.7"},{"introduced":"15.0"},{"fixed":"15.2"}]}},{"type":"GIT","repo":"https://github.com/xwiki/xwiki-platform","events":[{"introduced":"e1f21be62698d7f22f8c65e37629953820178c27"},{"fixed":"e6857070533992f14bb81691dcdf4c315792656d"},{"introduced":"96b4a230ee41ef74268c9720722f6473c705583d"},{"fixed":"7d8a0fa4bef8e285a5aa1e65d78d05e10f3800ab"},{"fixed":"41d7dca2d30084966ca6a7ee537f39ee8354a7e3"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.3"},{"fixed":"14.10.7"},{"introduced":"15.0"},{"fixed":"15.2"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50732.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}]}