CVE-2022-36098: XWiki Platform Mentions UI vulnerable to Cross-site Scripting
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor, or reference field. The stored code is executed by anyone visiting the page with the mention. This issue has been patched on XWiki 14.4 and 13.10.6. As a workaround, one may update XWiki.Mentions.MentionsMacro and edit the Macro code field of the XWiki.WikiMacroClass XObject.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36098?
CVE-2022-36098 has a medium severity rating.
How do I fix CVE-2022-36098?
To remediate CVE-2022-36098, upgrade XWiki Platform to version 13.10.6 or later, or version 14.4.
What versions are affected by CVE-2022-36098?
CVE-2022-36098 affects XWiki Platform versions from 12.5-rc-1 up to but not including 13.10.6 and 14.4.
What kind of scripts can be stored in the mention due to CVE-2022-36098?
CVE-2022-36098 allows the storage of Javascript or Groovy scripts within mentions or macro anchors.
Is there a workaround for CVE-2022-36098?
There are no known workarounds for CVE-2022-36098 other than upgrading to a secure version.