← Back

CVE-2024-31985

nvd nist
Published: Apr 10, 2024Modified: Jan 23, 2025

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictable URL, for example by embedding such an URL in any content as an image. The vulnerability has been fixed in XWiki 14.10.19, 15.5.5, and 15.9. As a workaround, manually apply the patch by modifying the `Scheduler.WebHome` page.

Affected (3)

Products: Xwiki: Xwiki
1 product
Xwiki
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Xwiki
From 15.0 to 15.5.4
From 15.6 to 15.9
From 3.1.1 to 14.10.19

References (12)

Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory

Timeline

No history available yet.