Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-19514

XSS using a JSX object

    XMLWordPrintable

Details

    • High
    • Unknown
    • N/A
    • N/A

    Description

      It's possible to perform a XSS in JSX "on demand" or "on this document" which don't requires PR, just by creating a new JSX with edit right, and waiting for a PR user to execute it when accessing the page.
      By doing so, we can request a PR user to create a page, or modify it, using any REST (or HTTP) request on the targeted wiki.
      Basically it allows privilege escalation.

      Attachments

        Issue Links

          Activity

            People

              surli Simon Urli
              surli Simon Urli
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: