Description
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
Remediation
References
Related Vulnerabilities
WordPress Plugin Akeeba Backup CORE for WordPress Arbitrary File Upload (1.1.3)
PHP CVE-2009-3292 Vulnerability (CVE-2009-3292)
WordPress Plugin Simple Dropbox Upload Arbitrary File Upload (1.8.8)
Mailman Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2021-42096)
WordPress Plugin Rezgo Online Booking Cross-Site Scripting (1.8.6)