AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-22457

CRITICAL · CVSS 9 EPSS 18.73% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-04 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.0. Public exploit code or proof-of-concept references have been detected in its references. Its EPSS score suggests a 18.7% probability of exploitation in the next 30 days. It may be remotely exploitable.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2023-22457
Severity
CRITICAL
CVSS
9
EPSS
18.73%

Original NVD Description

CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the rights of the current user. If a privileged user with programming rights was tricked into executing a GET request to this document with certain parameters (e.g., via an image with a corresponding URL embedded in a comment or via a redirect), this would allow arbitrary remote code execution and the attacker could gain rights, access private information or impact the availability of the wiki. The issue has been patched in the CKEditor Integration version 1.64.3. This has also been patched in the version of the CKEditor integration that is bundled starting with XWiki 14.6 RC1. There are no known workarounds for this other than upgrading the CKEditor integration to a fixed version.

Related CVEs

Other vulnerabilities affecting the same vendor(s)