CVE-2023-32070
CRITICALXwiki Rendering < 14.5 - XSS
Title source: ruleDescription
XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.
Exploits (1)
nomisec
STUB
by shoucheng3 · poc
https://github.com/shoucheng3/xwiki__xwiki-rendering_CVE-2023-32070_14-5
Scores
CVSS v3
9.0
EPSS
0.0466
EPSS Percentile
89.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-83
CWE-79
Status
published
Products (9)
org.xwiki.platform/xwiki-core-rendering-api
0Maven
org.xwiki.platform/xwiki-platform-annotation-core
0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-annotatedhtml5
0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-annotatedxhtml
0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-html
0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-html5
0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-xhtml
0 - 14.6-rc-1Maven
xwiki/rendering
3.0 milestone_2
xwiki/xwiki
< 14.5
Published
May 10, 2023
Tracked Since
Feb 18, 2026