XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data
Package
Affected versions
>= 12.10, < 13.10.10
>= 14.0, < 14.4.7
>= 14.5, < 14.9
Patched versions
13.10.10
14.4.7
14.9
Description
Published by the National Vulnerability Database
Mar 2, 2023
Published to the GitHub Advisory Database
Mar 3, 2023
Reviewed
Mar 3, 2023
Last updated
Mar 3, 2023
Impact
A user without script rights can introduce a stored XSS by using the Live Data macro.
For instance:
Patches
This has been patched in XWiki 14.9, 14.4.7, and 13.10.10.
Workarounds
No known workaround.
References
https://jira.xwiki.org/browse/XWIKI-20143
For more information
If you have any questions or comments about this advisory:
References