CVE-2023-45136
CVSS 3.1 Score 9.6 of 10 (high)
Details
Summary
CVE-2023-45136 is a reflected cross-site scripting (XSS) vulnerability affecting XWiki Platform, a widely-used wiki platform, starting from version 12.0-rc-1 and prior to 12.10.12 and 15.5-rc-1. The flaw lies in the page creation form, where document names are not properly validated, enabling an attacker to inject malicious scripts. Depending on the user's privileges, this vulnerability may result in remote code execution and full access to the XWiki installation. The root cause is the absence of appropriate escaping, which has been addressed in versions 14.10.12 and 15.5-rc-1. The affected template file, named `createinline.vm`, can be remedied by manually applying the patch from the fix.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xwiki
Affected Vendors
- xwiki