PT-2024-24347 · Unknown · Xwiki Platform

Michael Hamann

·

Published

2024-04-10

·

Updated

2025-01-09

·

CVE-2024-31997

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 4.10.19 XWiki Platform versions prior to 15.5.4 XWiki Platform versions prior to 15.10-rc-1
Description XWiki Platform is a generic wiki platform where parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document, like the user's own profile, can create UI extensions, allowing remote code execution and impacting the confidentiality, integrity, and availability of the whole XWiki installation.
Recommendations For versions prior to 4.10.19, update to version 4.10.19 or later. For versions prior to 15.5.4, update to version 15.5.4 or later. For versions prior to 15.10-rc-1, update to version 15.10-rc-1 or later. As a temporary workaround, consider restricting the creation of UI extensions to only trusted users until a patch is applied. Avoid using the label parameter in UI extensions to minimize the risk of exploitation.

Exploit

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-31997
GHSA-C2GG-4GQ4-JV5J

Affected Products

Xwiki Platform