QID 995716

Date Published: 2023-10-26

QID 995716: Java (Maven) Security Update for org.xwiki.platform:xwiki-platform-web (GHSA-93gh-jgjj-r929)

When trying to create a document that already exists, XWiki displays an error message in the form for creating it. Due to missing escaping, this error message is vulnerable to raw HTML injection and thus XSS. The injected code is the document reference of the existing document so this requires that the attacker first creates a non-empty document whose name contains the attack code.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-93gh-jgjj-r929 for updates and patch information.
    Vendor References

    CVEs related to QID 995716

    Software Advisories
    Advisory ID Software Component Link
    GHSA-93gh-jgjj-r929 org.xwiki.platform:xwiki-platform-web URL Logo github.com/advisories/GHSA-93gh-jgjj-r929