First published: Thu Sep 08 2022(Updated: )
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor, or reference field. The stored code is executed by anyone visiting the page with the mention. This issue has been patched on XWiki 14.4 and 13.10.6. As a workaround, one may update `XWiki.Mentions.MentionsMacro` and edit the `Macro code` field of the `XWiki.WikiMacroClass` XObject.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xwiki | >=12.5<13.10.6 | |
Xwiki | >=14.0<14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36098 has a medium severity rating.
To remediate CVE-2022-36098, upgrade XWiki Platform to version 13.10.6 or later, or version 14.4.
CVE-2022-36098 affects XWiki Platform versions from 12.5-rc-1 up to but not including 13.10.6 and 14.4.
CVE-2022-36098 allows the storage of Javascript or Groovy scripts within mentions or macro anchors.
There are no known workarounds for CVE-2022-36098 other than upgrading to a secure version.