CVE-2023-35155 is a Cross-Site Scripting (XSS) vulnerability affecting XWiki Platform versions prior to 15.0-rc-1, 14.10.4, and 14.4.8. This flaw allows an unauthenticated attacker to inject malicious JavaScript into a user's browser by crafting a specially designed URL. The vulnerability has a CVSS score of 6.1 (Medium), indicating a low attack complexity and requiring user interaction, but can lead to partial loss of confidentiality and integrity. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist, and the vulnerability has a high EPSS score suggesting potential for future exploitation. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.4.8CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 14.10, < 14.10.4CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.