Any user with edit right can execute arbitrary database select and access data stored in the database.
To reproduce:
The problem has been patched on XWiki 13.10.11, 14.4.7, and 14.10.
There is no workaround for this vulnerability other than upgrading.
https://jira.xwiki.org/browse/XWIKI-19523
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-284"
],
"github_reviewed": true,
"github_reviewed_at": "2023-03-03T22:46:43Z",
"nvd_published_at": "2023-03-02T19:15:00Z",
"severity": "MODERATE"
}