nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3137 CVE-2021-3137
MEDIUM
Cross Site Scripting (XSS) in XWiki
Record summary
CVE-2021-3137 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.
Description
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
org.xwiki.commons:xwiki-commonsBrowse Maven / org.xwiki.commons:xwiki-commons | GitHub Advisory | Before 12.10.3 · Fixed in 12.10.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBXwiki CMS 12.10.2 - Cross Site Scripting (XSS)ExploitDB exploitby Karan KeswaniNot analyzed1 file
References
2exploit-db.com
https://www.exploit-db.com/exploits/49437