Description
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This has been patched in XWiki 15.0-rc-1 and 14.10.4. There are no known workarounds.
Remediation
References
Related Vulnerabilities
WordPress Plugin Pinterest 'Pin It' Button Cross-Site Scripting (2.0.8)
WordPress Plugin Elementor Pro Cross-Site Scripting (2.0.9)
WordPress Plugin Tabs-Responsive Tabs with WooCommerce Product Tab Extension Security Bypass (3.6.0)
Atlassian Jira CVE-2021-39123 Vulnerability (CVE-2021-39123)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)