[MAVEN:GHSA-F963-4CQ8-2GW7] In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

Impact

A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor.
The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content.
The payload is executed at edit time.

Patches

This vulnerability has been patched in XWiki 15.10RC1.

Workarounds

No workaround. It is advised to upgrade to XWiki 15.10+.

References

For more information

If you have any questions or comments about this advisory:
* Open an issue in Jira XWiki.org
* Email us at Security Mailing List

Attribution

This vulnerability has been reported on Intigriti by @floerer

Package Affected Version
pkg:maven/org.xwiki.platform/xwiki-platform-web-templates < 15.10-rc-1
ID
MAVEN:GHSA-F963-4CQ8-2GW7
Severity
critical
URL
https://github.com/advisories/GHSA-f963-4cq8-2gw7
Published
2024-08-19T21:49:15
(4 weeks ago)
Modified
2024-08-19T21:49:15
(4 weeks ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.xwiki.platform/xwiki-platform-web-templates org.xwiki.platform xwiki-platform-web-templates < 15.10-rc-1
Fixed pkg:maven/org.xwiki.platform/xwiki-platform-web-templates org.xwiki.platform xwiki-platform-web-templates = 15.10-rc-1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...