PT-2023-4819 · Xwiki · Xwiki
Michael Hamann
·
Published
2023-06-29
·
Updated
2023-07-10
·
CVE-2023-36471
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
XWiki versions 14.6RC1 through 14.10.5
XWiki versions prior to 15.2RC1
Description
The issue arises from the HTML sanitizer in XWiki, which allowed form and input HTML tags since version 14.6RC1. This enables an attacker without script right to create forms for phishing attacks or add inputs that allow remote code execution when submitted by an admin. The attacker must ensure the edit form appears plausible, which can be challenging without script right.
Recommendations
For XWiki versions 14.6RC1 through 14.10.5, upgrade to version 14.10.6.
For XWiki versions prior to 15.2RC1, upgrade to version 15.2RC1.
As a temporary workaround, an admin can manually disallow the tags by adding
form, input, select, textarea, button to the configuration option xml.htmlElementSanitizer.forbidTags in the xwiki.properties configuration file.Exploit
Fix
Special Elements Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki