Remote Code Execution Vulnerability in XWiki Rendering Macros
CVE-2024-42489
8.8HIGH
Key Information:
- Vendor
- Xwikisas
- Status
- Xwiki-pro-macros
- Vendor
- CVE Published:
- 12 August 2024
Summary
The XWiki Pro Macros product includes various rendering macros, one of which is the Viewpdf macro. A critical flaw exists due to insufficient escaping in this macro, enabling any user with appropriate viewing, editing, or commenting rights on specified pages to execute arbitrary code remotely. This vulnerability similarly affects other macros, such as Viewppt, presenting a significant risk of unauthorized access or manipulation of the XWiki environment. The issue has been addressed in version 1.10.1, highlighting the necessity for users to update their installations promptly to safeguard against potential exploits.
Affected Version(s)
xwiki-pro-macros >= 1.0, < 1.10.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database