CVE-2022-36095 Information

Description

XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3 it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As a workaround one may locally modify the documentTags.vm template in one’s filesystem to apply the changes exposed there.

Reference

https://jira.xwiki.org/browse/XWIKI-19550 https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-fxwr-4vq9-9vhj https://github.com/xwiki/xwiki-platform/commit/7ca56e40cf79a468cea54d3480b6b403f259f9ae

Share on: