XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When document names are validated according to a name strategy (disabled by default), XWiki starting in version 12.0-rc-1 and prior to versions 12.10.12 and 15.5-rc-1 is vulnerable to a reflected cross-site scripting attack in the page creation form. This allows an attacker to execute arbitrary actions with the rights of the user opening the malicious link.
impact:|
Successful exploitation could lead to cross-site scripting attack.
remediation:|
This has been patched in XWiki 14.10.12 and 15.5-rc-1 by adding appropriate escaping.