QID 994954
Date Published: 2023-08-22
QID 994954: Java (Maven) Security Update for org.xwiki.platform:xwiki-platform-web-templates (GHSA-h8cm-3v5f-rgp6)
Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user preference. Even though the time zone is selected from a drop down (no free text value) it can still be set from JavaScript (using the browser developer tools) or by calling the save URL on the user profile with the right query string. Once the time zone is set it is displayed without escaping which means the payload gets executed for any user that visits the malicious user profile, allowing the attacker to steal information and even gain more access rights (escalation to programming rights).
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
- GHSA-h8cm-3v5f-rgp6 -
github.com/advisories/GHSA-h8cm-3v5f-rgp6
CVEs related to QID 994954
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h8cm-3v5f-rgp6 | org.xwiki.platform:xwiki-platform-web-templates |
|