PT-2023-22202 · Xwiki · Xwiki

Stuart Walker

·

Published

2023-04-12

·

Updated

2023-04-26

·

CVE-2023-29205

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 14.8RC1
Description The HTML macro in XWiki does not properly neutralize script-related HTML tags, allowing any user who can use the HTML macro to introduce an XSS attack. This is particularly dangerous in a standard wiki, where any user can use the HTML macro directly in their own user profile page.
Recommendations For versions prior to 14.8RC1, update to XWiki 14.8RC1 or later, which includes a patch that systematically cleans up the HTML macros whenever the user does not have the correct script rights. As a temporary workaround, consider restricting access to the HTML macro to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-29205
GHSA-VXF7-MX22-JR24

Affected Products

Xwiki