Description
XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11.
Published: 2023-04-16
Score: 8.9 High
EPSS: 4.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-1326 XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11.
Github GHSA Github GHSA GHSA-hmm7-6ph9-8jf2 org.xwiki.platform:xwiki-platform-livedata-macro vulnerable to Basic Cross-site Scripting
History

Thu, 06 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-06T16:14:25.016Z

Reserved: 2023-04-07T18:56:54.626Z

Link: CVE-2023-29508

cve-icon Vulnrichment

Updated: 2024-08-02T14:07:46.319Z

cve-icon NVD

Status : Analyzed

Published: 2023-04-16T08:15:07.513

Modified: 2025-04-11T14:50:31.367

Link: CVE-2023-29508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses