Description
XWiki Platform before 12.8 mishandles escaping in the property displayer.
Remediation
References
https://cve.nstsec.com/cve-2020-13654
https://github.com/xwiki/xwiki-platform/compare/xwiki-platform-12.7.1...xwiki-platform-12.8
https://github.com/xwiki/xwiki-platform/pull/1315
https://jira.xwiki.org/browse/XWIKI-17374
Related Vulnerabilities
CVE-2022-45146 Vulnerability in maven package org.bouncycastle:bc-fips-debug
CVE-2020-7740 Vulnerability in npm package node-pdf-generator
CVE-2019-5480 Vulnerability in npm package statichttpserver
CVE-2022-24771 Vulnerability in npm package node-forge
CVE-2018-18854 Vulnerability in maven package io.spray:spray-json_2.12