XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-1481 XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.
Github GHSA Github GHSA GHSA-6gf5-c898-7rxp Improper Neutralization of Script in Attributes in XWiki (X)HTML renderers
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 27 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-01-27T17:14:05.694Z

Reserved: 2023-05-01T16:47:35.314Z

Link: CVE-2023-32070

cve-icon Vulnrichment

Updated: 2024-08-02T15:03:28.935Z

cve-icon NVD

Status : Modified

Published: 2023-05-10T18:15:10.003

Modified: 2025-01-27T18:15:35.993

Link: CVE-2023-32070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.