Improper Neutralization of Alternate XSS Syntax in XWiki platform - CVE-2023-35160

 

Improper Neutralization of Alternate XSS Syntax in XWiki platform - CVE-2023-35160

Published: June 22, 2023 / Updated: May 5, 2026


Vulnerability identifier: #VU129943
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35160
CWE-ID: CWE-87
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary JavaScript in the page.

The vulnerability exists due to improper neutralization of alternate XSS syntax in the resubmit template when handling the xback and xcontinue URL parameters. A remote attacker can forge a URL with a crafted payload to inject arbitrary JavaScript in the page.

User interaction is required to open the crafted URL.


Affected software

XWiki platform

How to mitigate CVE-2023-35160

Install security update from vendor's website.

XWiki platform - addressed in versions 14.10.5, 15.1 rc-1

External References

Related Security Bulletins