Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41106
HistoryJul 03, 2023 - 5:09 a.m.

HTML Injection

2023-07-0305:09:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
html injection
xwiki-commons-xml
htmldefinitions
html sanitizer
malicious code
xwiki.

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

EPSS

0.002

Percentile

61.7%

xwiki-commons-xml is vulnerable to HTML Injection. The vulnerability exists because the HTMLDefinitions function in HTMLDefinitions.java does not properly disallow form-related tags in the HTML sanitizer, which allows an attacker to inject and execute malicious code such as {{html}}{{/html}} through the context of the XWiki.

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

EPSS

0.002

Percentile

61.7%

Related for VERACODE:41106