{"id":"CVE-2023-35153","summary":"XWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parameters","details":"XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exploited by users with edit rights by adding a `AppWithinMinutes.FormFieldCategoryClass` class on a page and setting the payload on the page title. Then, any user visiting `/xwiki/bin/view/AppWithinMinutes/ClassEditSheet` executes the payload. The issue has been patched in XWiki 14.4.8, 14.10.4, and 15.0. As a workaround, update `AppWithinMinutes.ClassEditSheet` with a patch.","aliases":["GHSA-4wc6-hqv9-qc97"],"modified":"2026-08-12T03:51:17.902897992Z","published":"2023-06-23T17:19:59.290Z","database_specific":{"cwe_ids":["CWE-79","CWE-80"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35153.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20365"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35153.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-4wc6-hqv9-qc97"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-35153"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/1b87fec1e5b5ec00b7a8c3c3f94f6c5e22547392#diff-79e725ec7125cced7d302e1a1f955a76745af26ef28a148981b810e85335d302"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xwiki/xwiki-commons","events":[{"introduced":"a1d7264bf87daf0a38602647504fe0590bd11ed5"},{"fixed":"48ee3193230753aecf8a86d7c8ff3e8f869e8330"},{"introduced":"719ede2f8510fa69498761659de8d65eec5817db"},{"fixed":"dfd0eff6a9f28f5a8840a5e4a51f0a24524c0280"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.4.4"},{"fixed":"14.4.8"},{"introduced":"14.10"},{"fixed":"14.10.4"}]}},{"type":"GIT","repo":"https://github.com/xwiki/xwiki-platform","events":[{"introduced":"4d2a2d9e9f29a4ffa7b6e230759f1e2fb21fa483"},{"fixed":"b469b950e7fe3d22f00b639d43f286bf871472b1"},{"introduced":"c524887d154ff8f6df9651e36b904e234bf5a6ef"},{"fixed":"c127075e7814ef7cd164bb6493d67b1943b6db1e"},{"fixed":"1b87fec1e5b5ec00b7a8c3c3f94f6c5e22547392"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.4.4"},{"fixed":"14.4.8"},{"introduced":"14.10"},{"fixed":"14.10.4"}]}}],"versions":["xwiki-commons-14.10.3","xwiki-commons-14.10.2","xwiki-commons-14.10.1","xwiki-commons-14.10","xwiki-platform-14.10.3","xwiki-platform-14.10.2","xwiki-platform-14.10.1","xwiki-platform-14.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-35153.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}