GHSA-ph5x-h23x-7q5q
Dashboard / Vulnerabilities / GHSA-ph5x-h23x-7q5q
Summary: Cross-site Scripting in wiki manager join wiki page
Details: ### Impact We found a possible XSS vector in the `WikiManager.JoinWiki ` wiki page related to the "requestJoin" field. ### Patches The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, 13.10.3. ### Workarounds The easiest workaround is to edit the wiki page `WikiManager.JoinWiki` (with wiki editor) and change the line ``` <input type='hidden' name='requestJoin' value="$!request.requestJoin"/> ``` into ``` <input type='hidden' name='requestJoin' value="$escapetool.xml($!request.requestJoin)"> ``` ### References * https://jira.xwiki.org/browse/XWIKI-19292 * https://github.com/xwiki/xwiki-platform/commit/27f839133d41877e538d35fa88274b50a1c00b9b ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki](https://jira.xwiki.org) * Email us at [security mailing list](mailto:[email protected])
References: https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-ph5x-h23x-7q5q, https://nvd.nist.gov/vuln/detail/CVE-2022-29252, https://github.com/xwiki/xwiki-platform/commit/27f839133d41877e538d35fa88274b50a1c00b9b, https://github.com/xwiki/xwiki-platform, https://jira.xwiki.org/browse/XWIKI-19292
Affected packages
Package
Name: org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
Purl: pkg:maven/org.xwiki.platform/xwiki-platform-wiki-ui-mainwiki
Affected ranges
Type: ECOSYSTEM
Events:
