CVE-2020-13654

XWiki Platform before 12.8 mishandles escaping in the property displayer.

Summary:

XWiki Platform before 12.8 mishandles escaping in the property displayer.

Reference Links(if available):

  • https://github.com/xwiki/xwiki-platform/compare/xwiki-platform-12.7.1…xwiki-platform-12.8
  • https://jira.xwiki.org/browse/XWIKI-17374
  • https://github.com/xwiki/xwiki-platform/pull/1315
  • CVSS Score (if available)

    v2: 5 / MEDIUM
    AV:N/AC:L/Au:N/C:P/I:N/A:N

    v3: 7.5 / HIGH
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

    Links to Exploits(if available)