Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wcg9-pgqv-xm5v

Опубликовано: 19 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 9.4
CVSS3: 9

Описание

XWiki Platform allows XSS through XClass name in string properties

Impact

Is it possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL.

Reproduction steps

  1. As a user without script or programming right, create a (non-terminal) document named " + alert(1) + " (the quotes need to be part of the name).
  2. Edit the class.
  3. Add a string property named "test".
  4. Edit using the object editor and add an object of the created class
  5. Get an admin to open <xwiki-server>/xwiki/bin/view/%22%20%2B%20alert(1)%20%2B%20%22/?viewer=display&type=object&property=%22%20%2B%20alert(1)%20%2B%20%22.WebHome.test&mode=edit where <xwiki-server> is the URL of your XWiki installation.

Patches

This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.

Workarounds

We're not aware of any workaround except upgrading.

References

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 1.1.2, < 14.10.21

14.10.21

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 15.0-rc-1, < 15.5.5

15.5.5

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 15.6-rc-1, < 15.10.6

15.10.6

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

= 16.0.0-rc-1

16.0.0

EPSS

Процентиль: 90%
0.05688
Низкий

9.4 Critical

CVSS4

9 Critical

CVSS3

Дефекты

CWE-79
CWE-96

Связанные уязвимости

CVSS3: 9
nvd
больше 1 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.

EPSS

Процентиль: 90%
0.05688
Низкий

9.4 Critical

CVSS4

9 Critical

CVSS3

Дефекты

CWE-79
CWE-96