Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in XWiki platform - CVE-2023-40176
Published: August 21, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to improper neutralization of script-related HTML tags in displayer_timezone.vm when displaying the time zone user preference in a user profile. A remote user can set a crafted time zone value through the profile save request to execute arbitrary script code in a victim's browser.
User interaction is required because a victim must visit the malicious user profile.