CVE-2022-36094: XWiki Platform Web Parent POM vulnerable to XSS in the attachment history
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing the history of an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3RC1. As a workaround, it is possible to replace viewattachrev.vm, the entry point for this attack, by a patched version from the patch without updating XWiki.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36094?
CVE-2022-36094 is considered a high severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2022-36094?
To address CVE-2022-36094, upgrade to XWiki version 13.10.6 or 14.30-rc-1 or later.
What types of applications are affected by CVE-2022-36094?
CVE-2022-36094 affects the XWiki platform, specifically versions from 1.0 up to 13.10.6 and from 14.0 up to 14.3.
What is the impact of CVE-2022-36094?
The impact of CVE-2022-36094 includes the execution of malicious JavaScript when users view attachment history.
Who is responsible for addressing CVE-2022-36094?
It is the responsibility of users and administrators of XWiki to apply the necessary updates to mitigate CVE-2022-36094.