Open redirect in XWiki platform - CVE-2023-29204
Published: April 12, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to url redirection to an untrusted site in redirect handling in xwiki-platform-oldcore when processing crafted redirect URLs. A remote attacker can supply a redirect value such as //mydomain.com or http:/mydomain.com to redirect users to an untrusted site.
User interaction is required.