← Back

CVE-2024-55877

nvd nist
Published: Dec 12, 2024Modified: Apr 30, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been fixed in XWiki 15.10.11, 16.4.1 and 16.5.0. It is possible to manually apply the patch to the page `XWiki.XWikiSyntaxMacrosList` as a workaround.

Affected (3)

Products: Xwiki: Xwiki
1 product
Xwiki
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Xwiki
From 16.0.0 to 16.4.1
From 9.7 to 15.10.11
Version 16.5.0 rc1

References (4)

Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
ExploitVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitVendor Advisory

Timeline

No history available yet.