CRITICAL 9.0 Maven

In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them

GHSA-f963-4cq8-2gw7 · CVE-2024-43401

Published · Modified

Description

Impact

A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor.
The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content.
The payload is executed at edit time.

Patches

This vulnerability has been patched in XWiki 15.10RC1.

Workarounds

No workaround. It is advised to upgrade to XWiki 15.10+.

References

For more information

If you have any questions or comments about this advisory:

Attribution

This vulnerability has been reported on Intigriti by @floerer

Ready to move

Start Securing

Free, no credit card | First findings in minutes