{"id":"CVE-2023-29506","aliases":["GHSA-jjm5-5v9v-7hx2"],"url":"https://o3.security/vulnerability/CVE-2023-29506","summary":"org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticated endpoints","details":"### Impact\n\nIt was possible to inject some code using the URL of authenticate endpoints, e.g.:\n\n```\nhttps://hostname/xwiki/authenticate/wiki/xwiki%22onload=%22alert(origin)%22/resetpassword\n```\n\nThis vulnerability was present in recent versions of XWiki:\n  - 13.10.8+\n  - 14.4.3+\n  - 14.6+\n\n### Patches\n\nThis problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.\n\n### Workarounds\nThere is no easy workaround except to upgrade.\n\n### References\n\n  - https://jira.xwiki.org/browse/XWIKI-20335\n  - https://github.com/xwiki/xwiki-platform/commit/1943ea26c967ef868fb5f67c487d98d97cba0380\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira](https://jira.xwiki.org)\n* Email us at [security mailing-list](mailto:security@xwiki.org)\n","published":"2023-04-16T06:49:51.376Z","modified":"2026-08-12T13:32:34.758735Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":{"score":0.01721,"percentile":0.76371,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-security-authentication-default","fixedVersion":"13.10.11"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-security-authentication-default","fixedVersion":"14.4.7"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-security-authentication-default","fixedVersion":"14.10"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/1943ea26c967ef868fb5f67c487d98d97cba0380","label":"xwiki/xwiki-platform@1943ea2"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20335"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29506.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jjm5-5v9v-7hx2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29506"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/1943ea26c967ef868fb5f67c487d98d97cba0380"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:32:34.758735Z"}}