HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax.
This has been patched in XWiki 14.6 RC1.
There are no known workarounds apart from upgrading to a fixed version.
If you have any questions or comments about this advisory: * Open an issue in Jira XWiki.org * Email us at Security Mailing List
{ "nvd_published_at": "2023-05-10T18:15:10Z", "cwe_ids": [ "CWE-79", "CWE-83" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-05-11T20:37:30Z" }