XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.xwiki.platform:xwiki-platform-index-tree-macro(Maven) | 8.3-rc-1 | 14.10.7 | N/A |
| org.xwiki.platform:xwiki-platform-index-tree-macro(Maven) | 15.0-rc-1 | 15.2-rc-1 | N/A |
CVSS Metrics