Michael Hamann

#122of 53,633
1038Total CVSS
Vulnerabilities · 114
Medium
12
High
22
Critical
80
PT-2024-36576
9.9
2024-12-12
Unknown · Xwiki Platform · CVE-2024-55662
**Name of the Vulnerable Software and Affected Versions** XWiki Platform versions 3.3-milestone-1 through 15.10.8 XWiki Platform versions 3.3-milestone-1 through 16.2.x **Description** XWiki Platform is a generic wiki platform. On instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This issue has been fixed in XWiki 15.10.9 and 16.3.0. Since `Extension Repository Application` is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page `ExtensionCode.ExtensionSheet` and to the page `ExtensionCode.ExtensionAuthorsDisplayer`. **Recommendations** For XWiki Platform versions 3.3-milestone-1 through 15.10.8, update to version 15.10.9 or later. For XWiki Platform versions 3.3-milestone-1 through 16.2.x, update to version 16.3.0 or later. As a temporary workaround, consider disabling the `Extension Repository Application` on instances that do not use it. Restrict access to the `ExtensionCode.ExtensionSheet` and `ExtensionCode.ExtensionAuthorsDisplayer` pages to minimize the risk of exploitation. Manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page `ExtensionCode.ExtensionSheet` and to the page `ExtensionCode.ExtensionAuthorsDisplayer` as an alternative solution.