{"id":"CVE-2023-37908","aliases":["GHSA-663w-2xp3-5739"],"url":"https://o3.security/vulnerability/CVE-2023-37908","summary":"org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability","details":"### Impact\nThe cleaning of attributes during XHTML rendering, introduced in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid attribute names. This can be exploited, e.g., via the link syntax in any content that supports XWiki syntax like comments in XWiki: \n\n```\n[[Link1>>https://XWiki.example.com||/onmouseover=\"alert('XSS1')\"]]\n```\n\nWhen a user moves the mouse over this link, the malicious JavaScript code is executed in the context of the user session. When this user is a privileged user who has programming rights, this allows server-side code execution with programming rights, impacting the confidentiality, integrity and availability of the XWiki instance.\n\nWhile this attribute was correctly recognized as not allowed, the attribute was still printed with a prefix `data-xwiki-translated-attribute-` without further cleaning or validation.\n\nNote that while versions below 14.6 are not vulnerable to this particular vulnerability, they are still vulnerable to XSS through attributes in XWiki syntax, see [the corresponding advisory](https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-6gf5-c898-7rxp).\n\n### Patches\nThis problem has been patched in XWiki 14.10.4 and 15.0 RC1 by removing characters not allowed in data attributes and then validating the cleaned attribute again.\n\n### Workarounds\nThere are no known workarounds apart from upgrading to a version including the fix.\n\n### References\n* https://jira.xwiki.org/browse/XRENDERING-697\n* https://github.com/xwiki/xwiki-rendering/commit/f4d5acac451dccaf276e69f0b49b72221eef5d2f\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki](https://jira.xwiki.org/)\n* Email us at [XWiki Security mailing-list](mailto:security@xwiki.org)\n","published":"2023-10-25T16:53:25.679Z","modified":"2026-08-12T14:50:53.554666Z","cvss":{"score":9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.rendering:xwiki-rendering-xml","fixedVersion":"14.10.4"}],"fix":{"url":"https://github.com/xwiki/xwiki-rendering/commit/f4d5acac451dccaf276e69f0b49b72221eef5d2f","label":"xwiki/xwiki-rendering@f4d5aca"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XRENDERING-697"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37908.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-663w-2xp3-5739"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-6gf5-c898-7rxp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37908"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-rendering/commit/f4d5acac451dccaf276e69f0b49b72221eef5d2f"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-rendering"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T14:50:53.554666Z"}}