PT-2024-24336 · Xwiki · Xwiki Platform

Michael Hamann

·

Published

2023-04-18

·

Updated

2025-01-21

·

CVE-2024-31986

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki Platform versions 3.1 through 4.10.18 XWiki Platform versions 14.10.18 and earlier XWiki Platform versions 15.5.4 and earlier XWiki Platform version 15.10-rc-1 and earlier
Description The issue allows execution of arbitrary code on the server whenever an admin visits the scheduler page or the scheduler page is referenced. This can be achieved by creating a document with a special crafted documented reference and an XWiki.SchedulerJobClass XObject.
Recommendations For XWiki Platform versions 3.1 through 4.10.18, update to version 4.10.19 or later. For XWiki Platform versions 14.10.18 and earlier, update to version 14.10.19 or later. For XWiki Platform versions 15.5.4 and earlier, update to version 15.5.5 or later. For XWiki Platform version 15.10-rc-1 and earlier, update to version 15.9 or later. As a temporary workaround, modify the Scheduler.WebHome page by applying the patch manually.

Exploit

Fix

Eval Injection

CSRF

Weakness Enumeration

Related Identifiers

BDU:2025-04026
CVE-2024-31986
GHSA-37M4-HQXV-W26G

Affected Products

Xwiki Platform