Description
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
Remediation
References
https://www.exploit-db.com/exploits/49437
Related Vulnerabilities
CVE-2023-26152 Vulnerability in npm package static-server
CVE-2023-40787 Vulnerability in maven package org.springblade:blade-core-tool
CVE-2019-14653 Vulnerability in maven package org.webjars.npm:editor.md
CVE-2022-25912 Vulnerability in maven package org.webjars.npm:simple-git
CVE-2018-20318 Vulnerability in maven package com.github.binarywang:weixin-java-common