First published: Thu Dec 31 2020(Updated: )
XWiki Platform before 12.8 mishandles escaping in the property displayer.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.xwiki.platform:xwiki-platform-web | <12.8 | 12.8 |
Xwiki | <12.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13654 has a medium severity rating due to its potential impact on the safety of user data.
To fix CVE-2020-13654, update your XWiki platform to version 12.8 or higher.
CVE-2020-13654 affects versions of the XWiki Platform prior to 12.8, specifically the property displayer functionality.
CVE-2020-13654 includes issues related to improper escaping, which can lead to security vulnerabilities like XSS attacks.
You can confirm your XWiki version by checking the application settings or the info page within the XWiki interface.