CVE-2024-43400

CVSS v3.1 5.4 (Medium)
54% Progress
EPSS 0.05 % (22th)
0.05% Progress
Affected Products 1
Advisories 1
NVD Status Analyzed

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-96
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
CVE Status
PUBLISHED
NVD Status
Analyzed
CNA
GitHub, Inc.
Published Date
2024-08-19 17:15:09
(4 weeks ago)
Updated Date
2024-08-20 16:10:29
(4 weeks ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Xwiki prior 14.10.21 version cpe:2.3:a:xwiki:xwiki < 14.10.21
  Xwiki from 15.0 version and prior 15.5.5 version cpe:2.3:a:xwiki:xwiki >= 15.0 < 15.5.5
  Xwiki from 15.6 version and prior 15.10.6 version cpe:2.3:a:xwiki:xwiki >= 15.6 < 15.10.6
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...