CVE-2023-40177: XWiki Platform privilege escalation (PR) from account through AWM content fields
Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus effectively performing rights escalation.
References
Detect and mitigate CVE-2023-40177 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →