Vulnerability record · CVE-2022-36097 · published 8 September 2022
CVE-2022-36097: XWiki Platform Attachment UI stored XSS via attachment name
Xwiki · Xwiki
XWiki Platform Attachment UI allows JavaScript to be stored in an attachment name, which is then executed when a user moves that attachment. The flaw affects versions from 14.0-rc-1 up to 14.4-rc-1 and is patched in 14.4-rc-1. Because the script runs in the context of the moving user, it can compromise sessions and perform actions as that user.
Description
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which will be executed by anyone trying to move the corresponding attachment. This issue has been patched in XWiki 14.4-rc-1. As a workaround, one may copy `moveStep1.vm` to `webapp/xwiki/templates/moveStep1.vm` and replace vulnerable code with code from the patch.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityAlthough CVSS is medium, the high EPSS score and public exploit references indicate active interest and a realistic risk for unpatched XWiki instances.
What it is
XWiki Platform Attachment UI allows JavaScript to be stored in an attachment name, which is then executed when a user moves that attachment. The flaw affects versions from 14.0-rc-1 up to 14.4-rc-1 and is patched in 14.4-rc-1. Because the script runs in the context of the moving user, it can compromise sessions and perform actions as that user.
Impact
An attacker can execute arbitrary JavaScript in the browser of any user who moves the malicious attachment, potentially stealing session cookies or performing actions with the victim's privileges. The CVSS vector indicates limited confidentiality and integrity impact within a changed scope.
Attack surface
The vulnerability is reachable over the network through the attachment move functionality. No authentication is required to trigger the stored payload, but user interaction is needed because a victim must attempt to move the affected attachment.
Exploitation
The record is not listed in CISA KEV, but EPSS is high at 0.57388 (99th percentile) and multiple references are tagged Exploit, indicating public exploit information exists.
What to do
- Upgrade to XWiki 14.4-rc-1 or later, which contains the patch.
- If immediate upgrade is not possible, apply the documented workaround by copying moveStep1.vm to webapp/xwiki/templates/moveStep1.vm and replacing the vulnerable code with the patched version.
- Restrict attachment upload and move permissions to trusted users until the patch is applied.
- Review and sanitize existing attachment names for embedded JavaScript or HTML.
- Monitor XWiki security advisories for any further updates or backports.
Detection
- Search XWiki attachment names for suspicious characters such as angle brackets, script tags, or JavaScript event handlers.
- Monitor web server and application logs for requests to the attachment move endpoint with unusual or encoded attachment names.
- Alert on unexpected JavaScript execution or DOM changes during attachment move operations in client-side monitoring.
- Audit user reports of unexpected pop-ups or redirects when moving attachments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/fbc4bfbae4f6ce8109addb281de86a03acdb9277 | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9r9j-57rf-f6vj | ExploitThird Party Advisory |
| https://jira.xwiki.org/browse/XWIKI-19667 | ExploitVendor Advisory |
| https://raw.githubusercontent.com/xwiki/xwiki-platform/xwiki-platform-14.0-rc-1/xwiki-platform-core/xwiki-platform-attac | ExploitThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/commit/fbc4bfbae4f6ce8109addb281de86a03acdb9277 | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9r9j-57rf-f6vj | ExploitThird Party Advisory |
| https://jira.xwiki.org/browse/XWIKI-19667 | ExploitVendor Advisory |
| https://raw.githubusercontent.com/xwiki/xwiki-platform/xwiki-platform-14.0-rc-1/xwiki-platform-core/xwiki-platform-attac | ExploitThird Party Advisory |
Track CVE-2022-36097 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36097), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.