Remote Code Execution Vulnerability in XWiki Rendering Macros
CVE-2024-42489
Key Information:
- Vendor
- Xwikisas
- Status
- Xwiki-pro-macros
- Vendor
- CVE Published:
- 12 August 2024
Summary
The XWiki Pro Macros product includes various rendering macros, one of which is the Viewpdf macro. A critical flaw exists due to insufficient escaping in this macro, enabling any user with appropriate viewing, editing, or commenting rights on specified pages to execute arbitrary code remotely. This vulnerability similarly affects other macros, such as Viewppt, presenting a significant risk of unauthorized access or manipulation of the XWiki environment. The issue has been addressed in version 1.10.1, highlighting the necessity for users to update their installations promptly to safeguard against potential exploits.
Affected Version(s)
xwiki-pro-macros >= 1.0, < 1.10.1
References
EPSS Score
55% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved