VYPR
High severityNVD Advisory· Published May 25, 2022· Updated Apr 23, 2025

Cross-site Scripting in XWiki Platform Wiki UI Main Wiki

CVE-2022-29252

Description

XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the WikiManager.JoinWiki wiki page related to the "requestJoin" field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page WikiManager.JoinWiki (with wiki editor) according to the suggestion provided in the GitHub Security Advisory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.xwiki.platform:xwiki-platform-wiki-ui-mainwikiMaven
< 12.10.1112.10.11
org.xwiki.platform:xwiki-platform-wiki-ui-mainwikiMaven
>= 13.0.0, < 13.4.713.4.7
org.xwiki.platform:xwiki-platform-wiki-ui-mainwikiMaven
>= 13.5.0, < 13.10.313.10.3

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.