Remote Code Execution Vulnerability in XWiki Platform
CVE-2024-31997
Summary
The XWiki Platform is susceptible to a significant security vulnerability that enables remote code execution through improperly handled parameters in UI extensions. Users who possess edit rights on documents—including their own profiles—can create malicious UI extensions that are executed with elevated programming rights. This flaw affects the confidentiality, integrity, and overall availability of the XWiki installation. It is crucial for users to update their systems to versions 4.10.19, 15.5.4, or 15.10-rc-1 to mitigate the risks associated with this vulnerability, as no workarounds exist.
Affected Version(s)
xwiki-platform < 14.10.19 < 14.10.19
xwiki-platform >= 15.0-rc-1, < 15.5.4 < 15.0-rc-1, 15.5.4
xwiki-platform >= 15.6-rc-1, < 15.9-rc-1 < 15.6-rc-1, 15.9-rc-1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved