VDB
Sign up
CRITICAL9.9

GHSA-vxf7-mx22-jr24

org.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macro

Quick fix

GHSA-vxf7-mx22-jr24 — org.xwiki.platform:xwiki-platform-rendering-xwiki: upgrade to the fixed version with the command below.

# pom.xml: bump <version>14.8-rc-1</version> for org.xwiki.platform:xwiki-platform-rendering-xwiki

Details

### Impact

The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS attack. This can be particularly dangerous since in a standard wiki, any user is able to use the html macro directly in their own user profile page.

### Patches

The problem has been patched in XWiki 14.8RC1. The patch involve that the HTML macro are systematically cleaned up whenever the user does not have script right.

### Workarounds

There's no workaround for this issue.

### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira](https://jira.xwiki.org) * Email us at [security ML](mailto:security@xwiki.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.xwiki.platform:xwiki-platform-rendering-xwiki
Introduced in: 0Fixed in: 14.8-rc-1
Fix# pom.xml: bump <version>14.8-rc-1</version> for org.xwiki.platform:xwiki-platform-rendering-xwiki

References