High severityNVD Advisory· Published May 25, 2022· Updated Apr 23, 2025
Cross-site Scripting in XWiki Platform Wiki UI Main Wiki
CVE-2022-29252
Description
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the WikiManager.JoinWiki wiki page related to the "requestJoin" field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page WikiManager.JoinWiki (with wiki editor) according to the suggestion provided in the GitHub Security Advisory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.xwiki.platform:xwiki-platform-wiki-ui-mainwikiMaven | < 12.10.11 | 12.10.11 |
org.xwiki.platform:xwiki-platform-wiki-ui-mainwikiMaven | >= 13.0.0, < 13.4.7 | 13.4.7 |
org.xwiki.platform:xwiki-platform-wiki-ui-mainwikiMaven | >= 13.5.0, < 13.10.3 | 13.10.3 |
Affected products
2- Range: >= 5.3-milestone-2, < 12.10.11
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-ph5x-h23x-7q5qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-29252ghsaADVISORY
- github.com/xwiki/xwiki-platform/commit/27f839133d41877e538d35fa88274b50a1c00b9bghsax_refsource_MISCWEB
- github.com/xwiki/xwiki-platform/security/advisories/GHSA-ph5x-h23x-7q5qghsax_refsource_CONFIRMWEB
- jira.xwiki.org/browse/XWIKI-19292ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.