XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-04-10T20:32:39.317Z
Updated: 2024-08-20T18:00:36.216Z
Reserved: 2024-04-08T13:48:37.490Z
Link: CVE-2024-31987
Vulnrichment
Updated: 2024-08-02T01:59:50.698Z
NVD
Status : Awaiting Analysis
Published: 2024-04-10T21:15:07.110
Modified: 2024-04-11T12:47:44.137
Link: CVE-2024-31987
Redhat
No data.