Cross-site Scripting in org.xwiki.commons:xwiki-commons-xml
CVE-2023-29528

9.1CRITICAL

Key Information:

Vendor

Xwiki

Vendor
CVE Published:
20 April 2023

What is CVE-2023-29528?

XWiki Commons has a vulnerability in its 'restricted' mode of the HTML cleaner that permits the injection of arbitrary HTML code through invalid HTML comments. This issue arises when a privileged user, who has programming rights, interacts with the malicious comment, leading to JavaScript execution within the user's session. The implications of this vulnerability could compromise the confidentiality, integrity, and availability of the XWiki instance. A fix was introduced in version 14.10, where the HTML comments are now sanitized in 'restricted' mode, and checks have been added to prevent starting comments with specific characters. Users are advised to upgrade to this version to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

xwiki-commons >= 4.2-milestone-1, < 14.10

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.