GHSA-35j5-m29r-xfq5
HIGHCVE-2023-37912The footnote macro executed its content in a potentially different context than the one in which it was defined. In particular in combination with the include macro, this allows privilege escalation from a simple user account in XWiki to programming rights and thus remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki installation.
- Affected
- < 14.10.6
- Fixed in
- 14.10.6
- Weakness
- CWE-270
- Published
- 2023-10-25
- Source
- github