XWiki Platform vulnerable to Cross-site Scripting in the deleted attachments list
Published Sep 8, 2022
9.0
CRITICALCVSS 3.1
EPSS 60.22%
Description
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3. As a workaround, modify fix the vulnerability by editing the wiki page `XWiki.DeletedAttachments` with the object editor, open the `JavaScriptExtension` object and apply on the content the changes that can be found on the fix commit.
Affected products
-
Affected
- ≥ 14.0, < 14.3
- ≥ 2.2-milestone-1, < 13.10.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Xwiki | Xwiki-Platform | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6824 Advisory
- https://github.com/advisories/GHSA-gjmq-x5x7-wc36 Advisory
- https://github.com/xwiki/xwiki-platform/commit/6705b0cd0289d1c90ed354bd4ecc1508c4b25745 x_refsource_MISCPatchThird Party Advisory
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-gjmq-x5x7-wc36 x_refsource_CONFIRMThird Party Advisory
- https://jira.xwiki.org/browse/XWIKI-19613 x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36096
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6824 | Advisory | |
| https://github.com/advisories/GHSA-gjmq-x5x7-wc36 | Advisory | |
| https://github.com/xwiki/xwiki-platform/commit/6705b0cd0289d1c90ed354bd4ecc1508c4b25745 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-gjmq-x5x7-wc36 | x_refsource_CONFIRMThird Party Advisory | |
| https://jira.xwiki.org/browse/XWIKI-19613 | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-36096 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub