GHSA-9pc2-x9qf-7j2q
CRITICALCVE-2023-29209Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the macro parameters of the [legacy notification activity macro](https://extensions.xwiki.org/xwiki/bin/view/Extension/Legacy%20Notification
- Affected
- >= 10.9, < 13.10.11, >= 14.5, < 14.10, >= 14.0-rc-1, < 14.4.7
- Fixed in
- 13.10.11
- Weakness
- CWE-94
- Published
- 2023-04-12
- Source
- github