XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.
Attacker without special permissions creates a crafted URL pointing to an XWiki page containing arbitrary JavaScript code (XSS). Then, using social engineering techniques, persuades an authenticated user to click on this link. When the page opens, the victim's browser executes the malicious script in the context of the XWiki application, which can lead to session theft, content modification, or further attack propagation.
Attacker can gain access to sensitive victim session data, modify wiki content, or perform actions on behalf of the attacked user. Due to CVSS 9.0 rating and scope of impact covering confidentiality, integrity, and availability, consequences can be very serious.
XWiki Platform should be updated to version 14.10.21, 15.5.5, 15.10.6, or 16.0.0, in which the vulnerability has been removed. Additionally, user education is recommended regarding recognition of suspicious links and phishing techniques.
XWiki Platform in versions prior to 14.10.21, 15.5.5, 15.10.6, and 16.0.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HXwiki
APPXwiki< 14.10.2115.0 – 15.5.5 (excl.)15.6 – 15.10.6 (excl.)
Related vulnerabilities
XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch
XWiki Platform — path traversal umożliwia odczyt plików konfiguracyjnych
XWiki Platform: ujawnienie plików konfiguracyjnych przez webjars API (path traversal)
SQL Injection w XWiki Platform via parametr sort w getdeleteddocuments.vm
XWiki Rendering: bypass trybu restricted przez zagnieżdżone makra