Impact
It was possible to inject some code using the URL of authenticate endpoints, e.g.:
https://hostname/xwiki/authenticate/wiki/xwiki%22onload=%22alert(origin)%22/resetpassword
This vulnerability was present in recent versions of XWiki:
Patches
This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.
Workarounds
There is no easy workaround except to upgrade.
References
For more information
If you have any questions or comments about this advisory:
Impact
It was possible to inject some code using the URL of authenticate endpoints, e.g.:
This vulnerability was present in recent versions of XWiki:
Patches
This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.
Workarounds
There is no easy workaround except to upgrade.
References
For more information
If you have any questions or comments about this advisory: