GHSA-vxf7-mx22-jr24
org.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macro
Quick fix
GHSA-vxf7-mx22-jr24 — org.xwiki.platform:xwiki-platform-rendering-xwiki: upgrade to the fixed version with the command below.
# pom.xml: bump <version>14.8-rc-1</version> for org.xwiki.platform:xwiki-platform-rendering-xwikiDetails
### Impact
The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS attack. This can be particularly dangerous since in a standard wiki, any user is able to use the html macro directly in their own user profile page.
### Patches
The problem has been patched in XWiki 14.8RC1. The patch involve that the HTML macro are systematically cleaned up whenever the user does not have script right.
### Workarounds
There's no workaround for this issue.
### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira](https://jira.xwiki.org) * Email us at [security ML](mailto:security@xwiki.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 14.8-rc-1# pom.xml: bump <version>14.8-rc-1</version> for org.xwiki.platform:xwiki-platform-rendering-xwiki