Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affecting org.xwiki.platform:xwiki-platform-attachment-ui package, versions [3.0-rc-1,13.10.11)[14.0-rc-1,14.4.8)[14.5,14.10.2)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.88% (83rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGXWIKIPLATFORM-5441634
  • published21 Apr 2023
  • disclosed20 Apr 2023
  • creditUnknown

Introduced: 20 Apr 2023

CVE-2023-29519  (opens in a new tab)
CWE-74  (opens in a new tab)

How to fix?

Upgrade org.xwiki.platform:xwiki-platform-attachment-ui to version 13.10.11, 14.4.8, 14.10.2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') such that a registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a gadget of their own dashboard.

Note: This vulnerability does not impact the comments of a wiki

CVSS Scores

version 3.1