Cross-site scripting in XWiki platform - CVE-2023-35155
Published: June 20, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary JavaScript in the page.
The vulnerability exists due to cross-site scripting in the share page target parameter when handling a forged URL. A remote attacker can send a specially crafted link to inject arbitrary JavaScript in the page.
User interaction is required to open the crafted link.