S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-35155 Scanner

CVE-2023-35155 Scanner - Cross-Site Scripting (XSS) vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-35155
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser: `<xwiki-host>/xwiki/bin/view/Main/?viewer=share&send=1&target=&target=%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Crenniepak%40intigriti.me%3E&includeDocument=inline&message=I+wanted+to+share+this+page+with+you.`, where `<xwiki-host>` is the URL of your XWiki installation. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
xwiki-platformby xwiki
>= 2.6-rc-2, < 14.4.8
Updated Aug 22, 2026View on NVD →
Detail

XWiki is a powerful open-source wiki platform used widely for building collaborative applications. It offers runtime services and is highly extensible, making it a popular choice for organizations needing comprehensive wiki functionalities. Many businesses and educational institutions use XWiki for documentation, content management, and as a knowledge base tool. Its capability to allow user customization and integration with various applications makes it robust for enterprise usage. The platform operates in a web server environment and serves as a crucial application for information sharing among team members. Additionally, XWiki’s design allows for the easy implementation of both structured and unstructured data.

The Cross-Site Scripting (XSS) vulnerability occurs when XWiki fails to properly sanitize user inputs. XSS allows attackers to inject malicious scripts into web applications, which are then executed in the context of a user's browser. This vulnerability can lead to unauthorized execution of scripts, potentially compromising sensitive user data. Attackers can perform actions on behalf of users, leading to data theft or unauthorized user actions. It primarily arises in areas of the application that handle user-generated content without proper validation and sanitation. This vulnerability is especially concerning as it can be exploited remotely without needing authentication.

Technically, this XSS vulnerability affects endpoints where user input is dynamically included in web pages without adequate filtering. The vulnerable parameter in XWiki is susceptible to script injections via forged URLs, allowing attackers to insert JavaScript code. Attackers can craft URLs that include script payloads which, upon visitation by users, execute within the context of the XWiki domain. This exposure often resides within page elements that accept user-generated content or dynamic URL parameters. Such inadequacies in content security policies or input validation create a vector for exploiting this XSS flaw. The specific vulnerability path includes query strings susceptible to manipulative script inputs.

If exploited by malicious parties, this vulnerability can lead to severe security issues. Unauthorized access to user sessions might occur, leading to data exposure and the potential for account takeovers. Attackers could extract sensitive information or intercept user interactions within the application. Moreover, the execution of malicious scripts could further propagate phishing attacks or redirect users to harmful sites. This could degrade trust in the application and result in reputational damage for the organizations utilizing XWiki. Ultimately, such vulnerabilities pose significant threats to data integrity and user privacy in the application.

REFERENCES

Solution Advice
  • Apply all available security patches and updates provided by XWiki to fix the vulnerability.
  • Implement input validation and sanitization to prevent future XSS attacks.
  • Use Content Security Policy (CSP) headers to mitigate script execution risks.
  • Conduct regular security audits and penetration testing to uncover and address new vulnerabilities promptly.
  • Educate users on safe browsing practices and recognizing phishing attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.