Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2676 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0. |
Github GHSA |
GHSA-wcg9-pgqv-xm5v | XWiki Platform allows XSS through XClass name in string properties |
Thu, 22 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:xwiki:xwiki-platform:16.0.0-rc-1:*:*:*:*:*:*:* |
Tue, 20 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki xwiki
|
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xwiki xwiki
|
Mon, 19 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki xwiki-platform |
|
| CPEs | cpe:2.3:a:xwiki:xwiki-platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xwiki
Xwiki xwiki-platform |
|
| Metrics |
ssvc
|
Mon, 19 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0. | |
| Title | XWiki Platform allows XSS through XClass name in string properties | |
| Weaknesses | CWE-96 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-22T14:00:37.297Z
Reserved: 2024-08-12T18:02:04.965Z
Link: CVE-2024-43400
Updated: 2024-08-19T18:01:19.455Z
Status : Analyzed
Published: 2024-08-19T17:15:09.097
Modified: 2024-08-20T16:10:29.987
Link: CVE-2024-43400
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA