Логотип exploitDog
bind:CVE-2023-26480
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-26480

Количество 2

Количество 2

nvd логотип

CVE-2023-26480

почти 3 года назад

XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known workarounds.

CVSS3: 8.9
EPSS: Низкий
github логотип

GHSA-32fq-m2q5-h83g

почти 3 года назад

XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data

CVSS3: 8.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-26480

XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known workarounds.

CVSS3: 8.9
1%
Низкий
почти 3 года назад
github логотип
GHSA-32fq-m2q5-h83g

XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data

CVSS3: 8.9
1%
Низкий
почти 3 года назад

Уязвимостей на страницу