CVE-2023-26480: XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data
Published Mar 2, 2023
·Updated
XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known workarounds.
Affected Software
4 affected components
XWiki xwiki>=12.10<13.10.10
XWiki xwiki>=14.0<14.4.7
XWiki xwiki>=14.5<14.9
XWiki xwiki=14.9-rc1
Remediation
Event History
Mar 2, 2023
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-26480?
CVE-2023-26480 has a critical severity as it allows stored cross-site scripting by users without script rights.
2
How do I fix CVE-2023-26480?
To fix CVE-2023-26480, you should upgrade to XWiki version 14.9, 14.4.7, or 13.10.10.
3
Which versions of XWiki are affected by CVE-2023-26480?
XWiki versions from 12.10 up to but not including 14.4.7, 14.9, and 13.10.10 are affected by CVE-2023-26480.
4
Are there any known workarounds for CVE-2023-26480?
There are no known workarounds for CVE-2023-26480; upgrading is the only solution.
5
What type of vulnerability is CVE-2023-26480?
CVE-2023-26480 is classified as a stored cross-site scripting (XSS) vulnerability.