XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As a workaround, one may locally modify the `documentTags.vm` template in one's filesystem, to apply the changes exposed there.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.xwiki.platform:xwiki-platform-web-templates(Maven) | 2.0-milestone-1 | 13.10.5 | N/A |
| org.xwiki.platform:xwiki-platform-web-templates(Maven) | 14.0 | 14.3 | N/A |
CVSS Metrics