Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-31987


XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading.


Published

2024-04-10T21:15:07.110

Last Modified

2025-01-21T15:35:42.450

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-862
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xwiki xwiki < 14.10.19 Yes
Application xwiki xwiki < 15.5.4 Yes
Application xwiki xwiki < 15.10 Yes

References