PT-2024-31694 · Unknown · Xwiki Platform
Xiqinger
·
Published
2024-09-10
·
Updated
2025-10-20
·
CVE-2024-45591
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
XWiki versions prior to 15.10.9
XWiki versions prior to 16.3.0RC1
Description
The XWiki Platform, a generic wiki platform, has an issue where its REST API exposes the history of any page if an attacker knows the page name. The exposed information includes the time of modification, version number, author (username and displayed name), and version comment for each page modification. This disclosure occurs regardless of permission settings, even on fully private wikis. The issue can be tested by accessing the
/xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history API endpoint. If the history of the main page is displayed, the installation is affected.Recommendations
For XWiki versions prior to 15.10.9, upgrade to version 15.10.9 or later.
For XWiki versions prior to 16.3.0RC1, upgrade to version 16.3.0RC1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki Platform