CVE-2023-37908 is a critical cross-site scripting (XSS) vulnerability in XWiki Rendering versions 14.6-rc-1 through 14.10.3 and 15.0 Beta 1. It allows arbitrary HTML injection via invalid attribute names during XHTML rendering, leading to malicious JavaScript execution when a user hovers over a crafted link. This can result in server-side code execution with programming rights for privileged users, severely impacting confidentiality, integrity, and availability. The vulnerability has a CVSS score of 9.6 (Critical) and is easily exploitable with low attack complexity and no user interaction beyond hovering. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.6, < 14.10.4CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki-rendering:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.