GHSA-fm68-j7ww-h9xf
CRITICALCVE-2023-36470By either creating a new or editing an existing document with an icon set, an attacker can inject XWiki syntax and Velocity code that is executed with programming rights and thus allows remote code execution. There are different attack vectors, the simplest is the Velocity code in the icon set's HTML or XWiki syntax definition. The [icon picker](https://extensions.xwiki.org/xwiki/bin/view/Extensio
- Affected
- >= 6.2-milestone-1, < 14.10.6, >= 15.0-rc-1, < 15.2-rc-1
- Fixed in
- 14.10.6
- Weakness
- CWE-74
- Published
- 2023-06-30
- Source
- github