PT-2023-8608 · Xwiki · Xwiki

Ynoof

·

Publicado

2023-04-20

·

Atualizado

2023-05-01

·

CVE-2023-29528

CVSS v3.1

9.0

Crítica

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki versions 4.2-milestone-1 through 14.10
Description The issue concerns the "restricted" mode of the HTML cleaner in XWiki, which allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid HTML comments. This vulnerability enables server-side code execution with programming rights, impacting the confidentiality, integrity, and availability of the XWiki instance. When a privileged user with programming rights visits a malicious comment, the JavaScript code is executed in the context of the user session.
Recommendations For versions prior to 14.10, upgrade to XWiki 14.10 or later, as it includes the fix where HTML comments are removed in restricted mode and a check is introduced to ensure comments don't start with >. At the moment, there is no other information about additional workarounds apart from upgrading to a version including the fix.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01261
CVE-2023-29528
GHSA-X37V-36WV-6V6H

Produtos afetados

Xwiki