Remote Code Execution Vulnerability in XWiki Rendering Macros
CVE-2024-42489

8.8HIGH

Key Information:

Vendor
Xwikisas
Status
Xwiki-pro-macros
Vendor
CVE Published:
12 August 2024

Summary

The XWiki Pro Macros product includes various rendering macros, one of which is the Viewpdf macro. A critical flaw exists due to insufficient escaping in this macro, enabling any user with appropriate viewing, editing, or commenting rights on specified pages to execute arbitrary code remotely. This vulnerability similarly affects other macros, such as Viewppt, presenting a significant risk of unauthorized access or manipulation of the XWiki environment. The issue has been addressed in version 1.10.1, highlighting the necessity for users to update their installations promptly to safeguard against potential exploits.

Affected Version(s)

xwiki-pro-macros >= 1.0, < 1.10.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.