PT-2023-8608 · Xwiki · Xwiki
Ynoof
·
Published
2023-04-20
·
Updated
2023-05-01
·
CVE-2023-29528
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki versions 4.2-milestone-1 through 14.10
Description
The issue concerns the "restricted" mode of the HTML cleaner in XWiki, which allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid HTML comments. This vulnerability enables server-side code execution with programming rights, impacting the confidentiality, integrity, and availability of the XWiki instance. When a privileged user with programming rights visits a malicious comment, the JavaScript code is executed in the context of the user session.
Recommendations
For versions prior to 14.10, upgrade to XWiki 14.10 or later, as it includes the fix where HTML comments are removed in restricted mode and a check is introduced to ensure comments don't start with
>.
At the moment, there is no other information about additional workarounds apart from upgrading to a version including the fix.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki