CVE-2012-1019
XWiki Enterprise 3.4 - Stored Cross-Site Scripting via Comment or User Profile Parameters
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in XWiki Enterprise 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) XWiki.XWikiComments_comment parameter to xwiki/bin/commentadd/Main/WebHome, (2) XWiki.XWikiUsers_0_company parameter when editing a user profile, or (3) projectVersion parameter to xwiki/bin/view/DownloadCode/DownloadFeedback. NOTE: some of these details are obtained from third party information.
References (4)
Core 4
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/47885
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/51867
Exploit x_refsource_misc
http://st2tea.blogspot.com/2012/02/xwiki-cross-site-scripting.html
Exploit x_refsource_misc
http://packetstormsecurity.org/files/109447/XWiki-Enterprise-3.4-Cross-Site-Scripting.html
Scores
EPSS
0.0006
EPSS Percentile
19.3%
Details
CWE
CWE-79
Status
published
Products (1)
xwiki/xwiki_enterprise
3.4
Published
Feb 08, 2012
Tracked Since
Feb 18, 2026