CVE-2022-29252: Cross-site Scripting in XWiki Platform Wiki UI Main Wiki
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the WikiManager.JoinWiki wiki page related to the "requestJoin" field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page WikiManager.JoinWiki (with wiki editor) according to the suggestion provided in the GitHub Security Advisory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29252?
CVE-2022-29252 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2022-29252?
To fix CVE-2022-29252, upgrade your XWiki Platform to the latest version that includes the security patch.
What versions of XWiki are affected by CVE-2022-29252?
CVE-2022-29252 affects versions from 5.3-milestone-2 to 13.4.7, excluding versions above 13.10.3.
What impact does CVE-2022-29252 have on XWiki installations?
The impact of CVE-2022-29252 allows an attacker to execute arbitrary scripts in the context of another user’s browser session.
Is CVE-2022-29252 related to any other vulnerabilities?
CVE-2022-29252 is specific to XWiki's WikiManager.JoinWiki functionality and does not share direct relation to other known vulnerabilities.