XWiki Platform vulnerable to RXSS via editor parameter - importinline template
Published May 9, 2023
9.1
CRITICALCVSS 3.1
EPSS 70.39%
Description
XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an attachment. This has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8. The easiest possible workaround is to edit file `<xwiki app>/templates/importinline.vm` and apply the modification described in commit 28905f7f518cc6f21ea61fe37e9e1ed97ef36f01.
Affected products
-
- Version >= 14.5, < 14.10.4StatusaffectedConstraints-
- Version >= 2.2-milestone-1, < 14.4.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Xwiki | Xwiki-Platform | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://app.intigriti.com/company/submissions/e95a7ad5-7029-4627-abf0-3e3e3ea0b4ce/XWIKI-E93DFEYK x_refsource_MISCPermissions Required
- https://github.com/advisories/GHSA-j9h5-vcgv-2jfm Advisory
- https://github.com/xwiki/xwiki-platform/commit/28905f7f518cc6f21ea61fe37e9e1ed97ef36f01 x_refsource_MISCPatch
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-j9h5-vcgv-2jfm x_refsource_CONFIRMVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-20340 x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-32071
| Link | Providers | Tags |
|---|---|---|
| https://app.intigriti.com/company/submissions/e95a7ad5-7029-4627-abf0-3e3e3ea0b4ce/XWIKI-E93DFEYK | x_refsource_MISCPermissions Required | |
| https://github.com/advisories/GHSA-j9h5-vcgv-2jfm | Advisory | |
| https://github.com/xwiki/xwiki-platform/commit/28905f7f518cc6f21ea61fe37e9e1ed97ef36f01 | x_refsource_MISCPatch | |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-j9h5-vcgv-2jfm | x_refsource_CONFIRMVendor Advisory | |
| https://jira.xwiki.org/browse/XWIKI-20340 | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-32071 |
Change history (0)
No recorded changes yet.