Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29207


XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also exploitable via the Documents Macro that is included since XWiki 3.5M1 and doesn't require script rights, this can be demonstrated with the syntax `{{documents id="example" count="5" actions="false" columns="doc.title, before<script>alert(1)</script>after"/}}`. Therefore, this can also be exploited by users without script right and in comments. With the interaction of a user with more rights, this could be used to execute arbitrary actions in the wiki, including privilege escalation, remote code execution, information disclosure, modifying or deleting content. This has been patched in XWiki 14.9, 14.4.6, and 13.10.10.


Published

2023-04-15T16:15:07.327

Last Modified

2024-11-21T07:56:42.957

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.9 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xwiki xwiki < 13.10.10 Yes
Application xwiki xwiki < 14.4.6 Yes
Application xwiki xwiki < 14.9 Yes
Application xwiki xwiki 1.9 Yes

References