XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS attack. This can be particularly dangerous since in a standard wiki, any user is able to use the html macro directly in their own user profile page. The problem has been patched in XWiki 14.8RC1. The patch involves the HTML macros and are systematically cleaned up whenever the user does not have the script correct.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-04-15T15:27:05.815Z
Updated: 2024-08-02T14:00:15.864Z
Reserved: 2023-04-03T13:37:18.454Z
Link: CVE-2023-29205
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-15T16:15:07.210
Modified: 2024-11-21T07:56:42.740
Link: CVE-2023-29205
Redhat
No data.