CRITICALMaven

org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converter

org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converter

CVE-2023-37913Published 2 years agoUpdated 5 days agoSource: OSV

Affected packages

  • org.xwiki.platform:xwiki-platform-office-importer3.5-milestone-1 → 14.10.8

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.