Description
XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.
Remediation
References
Related Vulnerabilities
XWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2023-45135)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4400)
WordPress Plugin Sliced Invoices-WordPress Invoice Multiple Vulnerabilities (3.8.2)
WordPress Plugin Shoppable Images Multiple Vulnerabilities (1.2.3)