Loading HuntDB...

GHSA-692v-783f-mg8x

GitHub Security Advisory

XWiki Platform vulnerable to Cross-Site Scripting (XSS) through conflict resolution

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

### Impact

By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confidentiality, integrity and availability of the whole XWiki installation.

To reproduce on a XWiki instance, a user with admin rights needs to edit a document without saving right away.
Then, as another user without any other right than edit on the specific document, change the whole content to `<script>alert('XSS')</script>`.
When the admin user then saves the document, a conflict popup appears. If they select "Fix each conflict individually" and see an alert displaying "XSS", then the instance is vulnerable.

### Patches

This has been patched in XWiki 15.10.8 and 16.3.0RC1.

### Workarounds

We're not aware of any workaround except upgrading.

### References

* https://jira.xwiki.org/browse/XWIKI-21626
* https://github.com/xwiki/xwiki-platform/commit/821d43ec45e67d45a6735a0717b9b77fffc1cd9f

### For more information

If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:[email protected])

Affected Packages

Maven org.xwiki.platform:xwiki-platform-web-templates
Affected versions: 11.8-rc-1 (fixed in 15.10.8)
Maven org.xwiki.platform:xwiki-platform-web-templates
Affected versions: 16.0.0-rc-1 (fixed in 16.3.0-rc-1)

Related CVEs

Key Information

GHSA ID
GHSA-692v-783f-mg8x
Published
July 31, 2024 4:54 PM
Last Modified
July 31, 2024 8:20 PM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
org.xwiki.platform:xwiki-platform-web-templates
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 22, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.