{"id":"GHSA-wvqx-m5px-6cmp","summary":"XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages","details":"### Impact\nA reflected cross site scripting (XSS) vulnerability in XWiki allows an attacker to execute arbitrary actions in XWiki with the rights of the victim if the attacker manages to trick a victim into visiting a crafted URL. If the victim has administrative or programming rights, those rights can be exploited to gain full access to the XWiki installation.\n\n### Patches\nThis vulnerability has been patched in XWiki 17.8.0RC1, 17.4.5 and 16.10.12.\n\n### Workarounds\nThe [patch](https://github.com/xwiki/xwiki-platform/commit/8337ac8c3b19c37f306723b638b2cae8b0a57dbf#diff-8f16efedd19baae025db602d8736a105bfd8f72676af2c935b8195a0c356ee71) can be applied manually, only a single line in `templates/logging_macros.vm` needs to be changed, no restart is required.\n\n### References\n* https://github.com/xwiki/xwiki-platform/commit/8337ac8c3b19c37f306723b638b2cae8b0a57dbf\n* https://jira.xwiki.org/browse/XWIKI-23462\n\n### Attribution\n\nWe thank Mike Cole @mikecole-mg for discovering and reporting this vulnerability.","aliases":["CVE-2026-24128"],"modified":"2026-02-03T03:07:15.865116Z","published":"2026-01-23T16:28:44Z","database_specific":{"nvd_published_at":"2026-01-24T00:15:49Z","cwe_ids":["CWE-79","CWE-80"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-01-23T16:28:44Z"},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-wvqx-m5px-6cmp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24128"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/8337ac8c3b19c37f306723b638b2cae8b0a57dbf"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/8337ac8c3b19c37f306723b638b2cae8b0a57dbf#diff-8f16efedd19baae025db602d8736a105bfd8f72676af2c935b8195a0c356ee71"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-16.10.12"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.5"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.8.0-rc-1"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-23462"}],"affected":[{"package":{"name":"org.xwiki.platform:xwiki-platform-web-templates","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-web-templates"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0-milestone-2"},{"fixed":"16.10.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-wvqx-m5px-6cmp/GHSA-wvqx-m5px-6cmp.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-web-templates","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-web-templates"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"17.0.0-rc-1"},{"fixed":"17.4.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-wvqx-m5px-6cmp/GHSA-wvqx-m5px-6cmp.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-web-templates","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-web-templates"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"17.5.0-rc-1"},{"fixed":"17.8.0-rc-1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-wvqx-m5px-6cmp/GHSA-wvqx-m5px-6cmp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"}]}