Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in XWiki platform - CVE-2023-29207

 

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in XWiki platform - CVE-2023-29207

Published: April 12, 2023 / Updated: May 5, 2026


Vulnerability identifier: #VU129990
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29207
CWE-ID: CWE-80
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary actions in the wiki.

The vulnerability exists due to improper neutralization of script-related html tags in the LiveTable Macro when rendering user-controlled column names. A remote user can inject crafted HTML or JavaScript through macro parameters to execute arbitrary actions in the wiki.

This issue is also exploitable via the Documents Macro and can be triggered in comments. User interaction is required by a user with more rights.


Affected software

XWiki platform

How to mitigate CVE-2023-29207

Install security update from vendor's website.

XWiki platform - addressed in versions 13.10.10, 14.4.6, 14.9

External References

Related Security Bulletins