{"id":"CVE-2022-36095","summary":"XWiki Cross-Site Request Forgery (CSRF) for actions on tags","details":"XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As a workaround, one may locally modify the `documentTags.vm` template in one's filesystem, to apply the changes exposed there.","aliases":["GHSA-fxwr-4vq9-9vhj"],"modified":"2026-08-12T03:51:18.618017553Z","published":"2022-09-08T20:20:13Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36095.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-352"]},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-19550"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36095.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-fxwr-4vq9-9vhj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36095"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/7ca56e40cf79a468cea54d3480b6b403f259f9ae"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xwiki/xwiki-commons","events":[{"introduced":"0"},{"fixed":"479a47aeb015f634a121f1821642e0cb61dcc3d7"},{"introduced":"491547c4f74b9be58123ef22081ae7e6840a11c7"},{"fixed":"58bca6b6f0fb325008ef9147d3c0cdda3e1e306b"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.3"},{"fixed":"13.10.6"},{"introduced":"14.0"},{"fixed":"14.3"}]}},{"type":"GIT","repo":"https://github.com/xwiki/xwiki-platform","events":[{"introduced":"1bf0361e80e94dd763901e3a863b4caaa24b6e17"},{"fixed":"c3f97150d6997ada95d919857fdc9690ed7ed316"},{"introduced":"d971304b0e0bf4f6dad278de89518edc17459741"},{"fixed":"585702c6749495ff837c791127e584668be87d74"},{"introduced":"f874012b54d1bf48592881472747080c5de5dbbf"},{"fixed":"7ca56e40cf79a468cea54d3480b6b403f259f9ae"}],"database_specific":{"extracted_events":[{"introduced":"2.3"},{"fixed":"13.10.6"},{"introduced":"14.0"},{"fixed":"14.3"},{"introduced":"2.0-milestone2"},{"last_affected":"2.0-milestone2"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","cpe:2.3:a:xwiki:xwiki:2.0:milestone2:*:*:*:*:*:*"]}}],"versions":["2.0-milestone2","xwiki-commons-14.3-rc-1","xwiki-commons-13.10.5","xwiki-commons-13.10.4","xwiki-commons-13.10.3","xwiki-commons-13.10.2","xwiki-commons-13.10.1","xwiki-commons-13.10","xwiki-commons-13.10-rc-1","xwiki-commons-8.3-milestone-2","xwiki-commons-8.3-milestone-1","xwiki-commons-8.2-milestone-2","xwiki-commons-8.2-milestone-1","xwiki-commons-8.1-milestone-2","xwiki-commons-8.1-milestone-1","xwiki-commons-8.0-milestone-2","xwiki-commons-8.0-milestone-1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36095.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}