Description
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
Remediation
References
https://www.exploit-db.com/exploits/49437
Related Vulnerabilities
CVE-2020-28480 Vulnerability in npm package jointjs
CVE-2017-17068 Vulnerability in maven package org.webjars.npm:auth0-js
CVE-2020-13822 Vulnerability in maven package org.webjars.npm:elliptic
CVE-2020-28447 Vulnerability in npm package xopen
CVE-2018-3739 Vulnerability in maven package org.webjars.npm:https-proxy-agent