GHSA-ph5x-h23x-7q5q
GitHub Security Advisory
Cross-site Scripting in wiki manager join wiki page
Advisory Details
### Impact
We found a possible XSS vector in the `WikiManager.JoinWiki ` wiki page related to the "requestJoin" field.
### Patches
The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, 13.10.3.
### Workarounds
The easiest workaround is to edit the wiki page `WikiManager.JoinWiki` (with wiki editor) and change the line
```
<input type='hidden' name='requestJoin' value="$!request.requestJoin"/>
```
into
```
<input type='hidden' name='requestJoin' value="$escapetool.xml($!request.requestJoin)">
```
### References
* https://jira.xwiki.org/browse/XWIKI-19292
* https://github.com/xwiki/xwiki-platform/commit/27f839133d41877e538d35fa88274b50a1c00b9b
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki](https://jira.xwiki.org)
* Email us at [security mailing list](mailto:[email protected])
Affected Packages
Related CVEs
Key Information
Dataset
Data from GitHub Advisory Database. This information is provided for research and educational purposes.