GHSA-fwwj-wg89-7h4c
Dashboard / Vulnerabilities / GHSA-fwwj-wg89-7h4c
Summary: XWiki Platform vulnerable to cross-site scripting in target parameter via share page by email
Details: ### Impact Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser: `<xwiki-host>/xwiki/bin/view/Main/?viewer=share&send=1&target=&target=%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Crenniepak%40intigriti.me%3E&includeDocument=inline&message=I+wanted+to+share+this+page+with+you.`, where `<xwiki-host>` is the URL of your XWiki installation. See https://jira.xwiki.org/browse/XWIKI-20370 for me details. ### Patches The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8. ### Workarounds The fix is only impacting Velocity templates and page contents, so applying this [patch](https://github.com/xwiki/xwiki-platform/commit/ca88ebdefb2c9fa41490959cce9f9e62404799e7) is enough to fix the issue. ### References https://jira.xwiki.org/browse/XWIKI-20370 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki.org](https://jira.xwiki.org/) * Email us at [Security Mailing List](mailto:[email protected]) ### Attribution This vulnerability has been reported on Intigriti by René de Sain @renniepak.
References: https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-fwwj-wg89-7h4c, https://nvd.nist.gov/vuln/detail/CVE-2023-35155, https://github.com/xwiki/xwiki-platform/commit/ca88ebdefb2c9fa41490959cce9f9e62404799e7, https://github.com/xwiki/xwiki-platform, https://jira.xwiki.org/browse/XWIKI-20370
Affected packages
Package
Name: org.xwiki.platform:xwiki-platform-sharepage-api
Purl: pkg:maven/org.xwiki.platform/xwiki-platform-sharepage-api
Affected ranges
Type: ECOSYSTEM
Events:
