{"id":"CVE-2024-43400","aliases":["GHSA-wcg9-pgqv-xm5v"],"url":"https://o3.security/vulnerability/CVE-2024-43400","summary":"XWiki Platform allows XSS through XClass name in string properties","details":"### Impact\nIs it possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript.\nThis requires social engineer to trick a user to follow the URL.\n\n#### Reproduction steps\n\n1. As a user without script or programming right, create a (non-terminal) document named `\" + alert(1) + \"` (the quotes need to be part of the name).\n1. Edit the class.\n1. Add a string property named `\"test\"`.\n1. Edit using the object editor and add an object of the created class\n1. Get an admin to open `<xwiki-server>/xwiki/bin/view/%22%20%2B%20alert(1)%20%2B%20%22/?viewer=display&type=object&property=%22%20%2B%20alert(1)%20%2B%20%22.WebHome.test&mode=edit` where `<xwiki-server>` is the URL of your XWiki installation.\n\n### Patches\nThis has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.\n\n### Workarounds\n\nWe're not aware of any workaround except upgrading.\n\n### References\n- https://jira.xwiki.org/browse/XWIKI-21810\n- https://github.com/xwiki/xwiki-platform/commit/27eca8423fc1ad177518077a733076821268509c\n","published":"2024-08-19T16:24:40.900Z","modified":"2026-08-12T15:15:28.981386Z","cvss":{"score":9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"},"epss":{"score":0.00488,"percentile":0.40924,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"14.10.21"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"15.5.5"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"15.10.6"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"16.0.0"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/27eca8423fc1ad177518077a733076821268509c","label":"xwiki/xwiki-platform@27eca84"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-21810"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/43xxx/CVE-2024-43400.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-wcg9-pgqv-xm5v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43400"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/27eca8423fc1ad177518077a733076821268509c"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:15:28.981386Z"}}