CVE-2023-36471
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-36471 is a vulnerability affecting Xwiki commons, the common modules used by various XWiki projects. The HTML sanitizer in XWiki, present since version 14.6RC1, unintentionally allowed form and input HTML tags. An attacker, without script rights, could exploit this by crafting a form or adding an input field with embedded Groovy code. This could lead to remote code execution when an admin submits the form, potentially resulting in phishing attacks or serious data breaches. The issue has been patched in XWiki versions 14.10.6 and 15.2RC1. Users are advised to upgrade as soon as possible. As a temporary measure, an admin can manually disallow the problematic tags (form, input, select, textarea, and button) by modifying the `xwiki.properties` configuration file.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- XWiki