PT-2024-31694 · Unknown · Xwiki Platform

Xiqinger

·

Published

2024-09-10

·

Updated

2025-10-20

·

CVE-2024-45591

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 15.10.9 XWiki versions prior to 16.3.0RC1
Description The XWiki Platform, a generic wiki platform, has an issue where its REST API exposes the history of any page if an attacker knows the page name. The exposed information includes the time of modification, version number, author (username and displayed name), and version comment for each page modification. This disclosure occurs regardless of permission settings, even on fully private wikis. The issue can be tested by accessing the /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history API endpoint. If the history of the main page is displayed, the installation is affected.
Recommendations For XWiki versions prior to 15.10.9, upgrade to version 15.10.9 or later. For XWiki versions prior to 16.3.0RC1, upgrade to version 16.3.0RC1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45591
GHSA-PVMM-55R5-G3MM

Affected Products

Xwiki Platform