Description The Image Import function in XWiki through 10.7 has XSS. Remediation References CVE-2018-16277 Related Vulnerabilities WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2019-17571) WordPress Plugin VDZ Google Analytics or Google Tag Manager/GTM Cross-Site Scripting (1.5.5) WordPress Plugin Download Monitor Cross-Site Scripting (3.3.6.1) Chamilo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-20329) PHP Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2008-3659) Severity Medium Classification CVE-2018-16277 CWE-707 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities