XSS vulnerability in CMS context-menu and the repository StatusServlet
Issue date: 04-04-2022Affects versions: 14.7, 13.4
Security Issue ID
SECURITY-270
Affected Product Version(s)
14.7.3, 13.4.14 and previous releases
Severity
normal
Description
The Wicket code that renders the javascript for displaying a context-menu in the Content Perspective allowed a logged-in user to execute javascript, because it did not escape request-parameters correctly.
Another issue was found with the Repository Status servlet which did not properly escape the message and stacktrace of an exception.
Instructions
Customers are recommended to upgrade to the latest version. As of the time of writing, 14.7.5 or 13.4.16.