First published: Wed Jan 20 2021(Updated: )
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xwiki | =12.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3137 is classified as a medium severity vulnerability.
To fix CVE-2021-3137, update XWiki to a version later than 12.10.2 that addresses this vulnerability.
CVE-2021-3137 is a Cross-Site Scripting (XSS) vulnerability.
Users of XWiki version 12.10.2 are affected by CVE-2021-3137.
CVE-2021-3137 allows attackers to execute arbitrary scripts in the context of the user's browser.