GHSA-c885-89fw-55qr
CRITICALCVE-2023-29202The [RSS macro](https://extensions.xwiki.org/xwiki/bin/view/Extension/RSS%20Macro) that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter content was set to true. This allowed arbitrary HTML and in particular also JavaScript injection and thus cross-site scripting (XSS) by specifying an RSS feed with malicious content. With the in
- Affected
- < 14.6-rc-1
- Fixed in
- 14.6-rc-1
- Weakness
- CWE-79
- Published
- 2023-04-12
- Source
- github