Description
XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exploited by users with edit rights by adding a `AppWithinMinutes.FormFieldCategoryClass` class on a page and setting the payload on the page title. Then, any user visiting `/xwiki/bin/view/AppWithinMinutes/ClassEditSheet` executes the payload. The issue has been patched in XWiki 14.4.8, 14.10.4, and 15.0. As a workaround, update `AppWithinMinutes.ClassEditSheet` with a patch.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.0.x Cross-Site Scripting (3.0.0 - 3.0.3)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Multiple Vulnerabilities (4.1.2)
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.29)
OpenSSL Out-of-bounds Write Vulnerability (CVE-2023-6129)
WordPress Plugin WP Gravity Forms Insightly Cross-Site Scripting (1.0.6)