XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-1326 XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11.
Github GHSA Github GHSA GHSA-hmm7-6ph9-8jf2 org.xwiki.platform:xwiki-platform-livedata-macro vulnerable to Basic Cross-site Scripting
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 06 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-06T16:14:25.016Z

Reserved: 2023-04-07T18:56:54.626Z

Link: CVE-2023-29508

cve-icon Vulnrichment

Updated: 2024-08-02T14:07:46.319Z

cve-icon NVD

Status : Analyzed

Published: 2023-04-16T08:15:07.513

Modified: 2025-04-11T14:50:31.367

Link: CVE-2023-29508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.