Description
PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.
Remediation
References
Related Vulnerabilities
Ruby Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2011-1004)
WordPress Plugin SnapApp Multiple Cross-Site Scripting Vulnerabilities (1.5)
WordPress Plugin User Self Delete SQL Injection (1.1)
Moodle Improper Encoding or Escaping of Output Vulnerability (CVE-2021-40694)