{"id":"GHSA-p93c-h8qm-7256","summary":"Improper escaping in XWiki Platform","details":"XWiki Platform before 12.8 mishandles escaping in the property displayer.","aliases":["CVE-2020-13654"],"modified":"2024-05-02T19:36:08Z","published":"2022-02-09T22:32:29Z","database_specific":{"cwe_ids":["CWE-116"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-04-07T19:52:54Z","nvd_published_at":"2020-12-31T01:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13654"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/pull/1315"},{"type":"WEB","url":"https://cve.anastasi.link/cve-2020-13654"},{"type":"WEB","url":"https://cve.nstsec.com/cve-2020-13654"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/compare/xwiki-platform-12.7.1...xwiki-platform-12.8"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-17374"}],"affected":[{"package":{"name":"org.xwiki.platform:xwiki-platform-web","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-p93c-h8qm-7256/GHSA-p93c-h8qm-7256.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}