Description
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
Remediation
References
https://www.exploit-db.com/exploits/49437
Related Vulnerabilities
CVE-2020-6428 Vulnerability in npm package electron
CVE-2023-34617 Vulnerability in maven package com.owlike:genson
CVE-2020-15126 Vulnerability in npm package parse-server
CVE-2022-4640 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2021-29444 Vulnerability in npm package jose-browser-runtime