Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTQzaGctZzQ0cS00NzRx

Cross Site Scripting (XSS) in XWiki

XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.

Permalink: https://github.com/advisories/GHSA-43hg-g44q-474q
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTQzaGctZzQ0cS00NzRx
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 3 years ago
Updated: over 1 year ago


Identifiers: GHSA-43hg-g44q-474q, CVE-2021-3137
References: Blast Radius: 0.0

Affected Packages

maven:org.xwiki.commons:xwiki-commons
Dependent packages: 0
Dependent repositories: 1
Downloads:
Affected Version Ranges: < 12.10.3
Fixed in: 12.10.3
All affected versions:
All unaffected versions: 12.10.11, 13.4.6, 13.4.7, 13.10.2, 13.10.3, 13.10.4, 13.10.5, 13.10.6, 13.10.7, 13.10.8, 13.10.9, 13.10.10, 13.10.11, 14.2.1, 14.3.1, 14.4.1, 14.4.2, 14.4.3, 14.4.4, 14.4.5, 14.4.6, 14.4.7, 14.4.8, 14.10.1, 14.10.2, 14.10.3, 14.10.4, 14.10.5, 14.10.6, 14.10.7, 14.10.8, 14.10.9, 14.10.10, 14.10.11, 14.10.12, 14.10.13, 14.10.14, 14.10.15, 14.10.16, 14.10.17, 14.10.18, 14.10.19, 14.10.20, 14.10.21, 15.5.1, 15.5.2, 15.5.3, 15.5.4, 15.5.5, 15.10.1, 15.10.2, 15.10.3, 15.10.4, 15.10.5, 15.10.6, 15.10.7, 15.10.8, 16.0.0, 16.1.0, 16.2.0, 16.3.0, 16.3.1