CVE-2023-35155

CVSS v3.1 6.1 (Medium)
61% Progress
EPSS 0.14 % (50th)
0.14% Progress
Affected Products 1
Advisories 1

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an alter on the browser: <xwiki-host>/xwiki/bin/view/Main/?viewer=share&send=1&target=&target=%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Crenniepak%40intigriti.me%3E&includeDocument=inline&message=I+wanted+to+share+this+page+with+you., where <xwiki-host> is the URL of your XWiki installation. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
GitHub, Inc.
Published Date
2023-06-23 19:15:09
(15 months ago)
Updated Date
2023-06-30 13:09:38
(14 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Xwiki prior 14.4.8 version cpe:2.3:a:xwiki:xwiki < 14.4.8
  Xwiki from 14.10 version and prior 14.10.4 version cpe:2.3:a:xwiki:xwiki >= 14.10 < 14.10.4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...