CVE-2023-32070
CRITICALXWiki Platform < 14.6-rc-1 - Cross-Site Scripting via HTML Attribute Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-32070. PoCs published by shoucheng3.
AI-analyzed exploit summary The repository contains only source code files from the XWiki Rendering project and a README, with no exploit PoC or offensive techniques present. It appears to be a partial snapshot of the project rather than a functional exploit.
Description
XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.
Exploits (1)
The repository contains only source code files from the XWiki Rendering project and a README, with no exploit PoC or offensive techniques present. It appears to be a partial snapshot of the project rather than a functional exploit.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H