XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1.
History

Wed, 21 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki xwiki-platform
CPEs cpe:2.3:a:xwiki:xwiki-platform:*:*:*:*:*:*:*:*
Vendors & Products Xwiki xwiki-platform
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki
Xwiki xwiki
Weaknesses CWE-862
CPEs cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
Vendors & Products Xwiki
Xwiki xwiki

Mon, 19 Aug 2024 16:45:00 +0000

Type Values Removed Values Added
Description XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1.
Title In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-19T16:24:29.698Z

Updated: 2024-08-21T14:23:29.403Z

Reserved: 2024-08-12T18:02:04.965Z

Link: CVE-2024-43401

cve-icon Vulnrichment

Updated: 2024-08-21T14:23:20.796Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-19T17:15:09.317

Modified: 2024-08-20T16:09:23.747

Link: CVE-2024-43401

cve-icon Redhat

No data.