Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in XWiki platform - CVE-2022-36094

 

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in XWiki platform - CVE-2022-36094

Published: September 8, 2022 / Updated: May 5, 2026


Vulnerability identifier: #VU130015
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36094
CWE-ID: CWE-80
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser.

The vulnerability exists due to improper neutralization of script-related HTML tags in the attachment history when rendering the history of an attachment with JavaScript in its name. A remote user can upload an attachment with a specially crafted filename to execute arbitrary JavaScript in the victim's browser.

User interaction is required to view the history of the crafted attachment.


Affected software

XWiki platform

How to mitigate CVE-2022-36094

Install security update from vendor's website.

XWiki platform - addressed in versions 13.10.6, 14.3 rc-1

External References

Related Security Bulletins