Impact
AbstractSxExportURLFactoryActionHandler#processSx does not escape anything from SSX document reference when serializing it on filesystem, so it's easy to mess up the HTML export process with reference elements containing filesystem syntax like "../", "./". or "/" in general (the last two not causing any security threat, but can cause conflicts with others serialized files).
Patches
Fixed in 13.6-rc-1
Workarounds
- giving script or subwiki admin right only to trusted people
- disabling HTML/PDF export
References
https://jira.xwiki.org/browse/XWIKI-18819
For more information
If you have any questions or comments about this advisory:
Impact
AbstractSxExportURLFactoryActionHandler#processSx does not escape anything from SSX document reference when serializing it on filesystem, so it's easy to mess up the HTML export process with reference elements containing filesystem syntax like "../", "./". or "/" in general (the last two not causing any security threat, but can cause conflicts with others serialized files).
Patches
Fixed in 13.6-rc-1
Workarounds
References
https://jira.xwiki.org/browse/XWIKI-18819
For more information
If you have any questions or comments about this advisory: