PT-2023-4819 · Xwiki · Xwiki

Michael Hamann

·

Published

2023-06-29

·

Updated

2023-07-10

·

CVE-2023-36471

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XWiki versions 14.6RC1 through 14.10.5 XWiki versions prior to 15.2RC1
Description The issue arises from the HTML sanitizer in XWiki, which allowed form and input HTML tags since version 14.6RC1. This enables an attacker without script right to create forms for phishing attacks or add inputs that allow remote code execution when submitted by an admin. The attacker must ensure the edit form appears plausible, which can be challenging without script right.
Recommendations For XWiki versions 14.6RC1 through 14.10.5, upgrade to version 14.10.6. For XWiki versions prior to 15.2RC1, upgrade to version 15.2RC1. As a temporary workaround, an admin can manually disallow the tags by adding form, input, select, textarea, button to the configuration option xml.htmlElementSanitizer.forbidTags in the xwiki.properties configuration file.

Exploit

Fix

Special Elements Injection

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-05282
CVE-2023-36471
GHSA-6PQF-C99P-758V

Affected Products

Xwiki