The Image Import function in XWiki through 10.7 has XSS.
References
Link | Resource |
---|---|
https://mksec.tk/index.php/2018/09/27/cve-2018-16277-xss-in-xwiki/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-09-27 17:29
Updated : 2018-11-15 10:14
NVD link : CVE-2018-16277
Mitre link : CVE-2018-16277
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
xwiki
- xwiki