Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vulnerability is fixed in 1.10.1.
History

Mon, 16 Sep 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki
Xwiki pro Macros
CPEs cpe:2.3:a:xwiki:pro_macros:*:*:*:*:*:*:*:*
Vendors & Products Xwiki
Xwiki pro Macros

Tue, 13 Aug 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Xwikisas
Xwikisas xwiki-pro-macros
CPEs cpe:2.3:a:xwikisas:xwiki-pro-macros:*:*:*:*:*:*:*:*
Vendors & Products Xwikisas
Xwikisas xwiki-pro-macros
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
Description Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vulnerability is fixed in 1.10.1.
Title Pro Macros Remote Code Execution via Viewpdf and similar macros
Weaknesses CWE-74
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-12T15:49:18.935Z

Updated: 2024-08-13T20:43:35.138Z

Reserved: 2024-08-02T14:13:04.618Z

Link: CVE-2024-42489

cve-icon Vulnrichment

Updated: 2024-08-13T20:43:29.481Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T16:15:16.667

Modified: 2024-09-16T19:46:18.913

Link: CVE-2024-42489

cve-icon Redhat

No data.