Vulnerability Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the delete template to perform a XSS, e.g. by using URL such as: > xwiki/bin/get/FlamingoThemes/Cerulean?xpage=xpart&vm=delete.vm&xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 6.0-rc-1. The vulnerability has been patched in XWiki 14.10.6 and 15.1. Note that a partial patch has been provided in 14.10.5 but wasn't enough to entirely fix the vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Xwiki | >= 6.0.1, < 14.10.6 |
Related Weaknesses (CWE)
References
- https://github.com/xwiki/xwiki-platform/commit/13875a6437d4525ac4aeea25918f2d2dfPatchVendor Advisory
- https://github.com/xwiki/xwiki-platform/commit/24ec12890ac7fa6daec8d0b3435cfcba1PatchVendor Advisory
- https://github.com/xwiki/xwiki-platform/commit/e80d22d193df364b07bab7925572720f9PatchVendor Advisory
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-834c-x29c-f42cVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-20341Issue TrackingVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-20583Issue TrackingVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-20672Issue TrackingVendor Advisory
- https://github.com/xwiki/xwiki-platform/commit/13875a6437d4525ac4aeea25918f2d2dfPatchVendor Advisory
- https://github.com/xwiki/xwiki-platform/commit/24ec12890ac7fa6daec8d0b3435cfcba1PatchVendor Advisory
- https://github.com/xwiki/xwiki-platform/commit/e80d22d193df364b07bab7925572720f9PatchVendor Advisory
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-834c-x29c-f42cVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-20341Issue TrackingVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-20583Issue TrackingVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-20672Issue TrackingVendor Advisory
FAQ
What is CVE-2023-35156?
CVE-2023-35156 is a vulnerability with a CVSS score of 9.6 (CRITICAL). XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). ...
How severe is CVE-2023-35156?
CVE-2023-35156 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-35156?
Check the references section above for vendor advisories and patch information. Affected products include: Xwiki Xwiki.