vendor:
Xwiki CMS
by:
Karan Keswani
7.5
CVSS
HIGH
Cross Site Scripting (XSS)
79
CWE
Product Name: Xwiki CMS
Affected Version From: 12.10.2
Affected Version To: 12.10.2
Patch Exists: YES
Related CWE: N/A
CPE: a:xwiki:xwiki_enterprise:12.10.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2021
Xwiki CMS 12.10.2 – Cross Site Scripting (XSS)
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.