CVE-2023-29206: org.xwiki.platform:xwiki-platform-skin-skinx vulnerable to basic Cross-site Scripting by exploiting JSX or SSX plugins
XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object and to craft a script allowing to perform some operations when executing by a user with appropriate rights. This has been patched in XWiki 14.9-rc-1 by only executing the script if the author of it has Script rights.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29206?
The severity of CVE-2023-29206 is critical with a score of 5.4.
How does CVE-2023-29206 impact XWiki?
CVE-2023-29206 allows a user with Edit Right to create a JavaScript xobject or StyleSheet xobject and craft a script, posing a security risk.
Which software versions are affected by CVE-2023-29206?
Versions 3.0 to 14.8 of XWiki are affected by CVE-2023-29206.
How can CVE-2023-29206 be mitigated?
To mitigate CVE-2023-29206, it is recommended to update XWiki to a version that includes the fix provided in the referenced commit or advisory.
Where can I find more information about CVE-2023-29206?
More information about CVE-2023-29206 can be found in the linked references.