CVE-2023-35155 – org.xwiki.platform:xwiki-platform-sharepage-api
Package
Manager: maven
Name: org.xwiki.platform:xwiki-platform-sharepage-api
Vulnerable Version: >=2.6-rc-2 <14.4.8 || >=14.5 <14.10.4
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS: 0.47027 pctl0.97605
Details
XWiki Platform vulnerable to cross-site scripting in target parameter via share page by email ### Impact Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser: `<xwiki-host>/xwiki/bin/view/Main/?viewer=share&send=1&target=&target=%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Crenniepak%40intigriti.me%3E&includeDocument=inline&message=I+wanted+to+share+this+page+with+you.`, where `<xwiki-host>` is the URL of your XWiki installation. See https://jira.xwiki.org/browse/XWIKI-20370 for me details. ### Patches The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8. ### Workarounds The fix is only impacting Velocity templates and page contents, so applying this [patch](https://github.com/xwiki/xwiki-platform/commit/ca88ebdefb2c9fa41490959cce9f9e62404799e7) is enough to fix the issue. ### References https://jira.xwiki.org/browse/XWIKI-20370 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki.org](https://jira.xwiki.org/) * Email us at [Security Mailing List](mailto:security@xwiki.org) ### Attribution This vulnerability has been reported on Intigriti by René de Sain @renniepak.
Metadata
Created: 2023-06-20T16:48:36Z
Modified: 2023-06-26T16:37:59Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-fwwj-wg89-7h4c/GHSA-fwwj-wg89-7h4c.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-fwwj-wg89-7h4c
Finding: F008
Auto approve: 1