XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed in XWiki 15.10.9 and 16.3.0. Since `Extension Repository Application` is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page `ExtensionCode.ExtensionSheet` and to the page `ExtensionCode.ExtensionAuthorsDisplayer`.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  Github GHSA | 
                GHSA-j2pq-22jj-4pm5 | XWiki allows remote code execution through the extension sheet | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Wed, 30 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Xwiki
         Xwiki xwiki  | 
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Xwiki
         Xwiki xwiki  | 
Fri, 13 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 12 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed in XWiki 15.10.9 and 16.3.0. Since `Extension Repository Application` is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page `ExtensionCode.ExtensionSheet` and to the page `ExtensionCode.ExtensionAuthorsDisplayer`. | |
| Title | XWiki allows remote code execution through the extension sheet | |
| Weaknesses | CWE-863 CWE-96  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-13T14:59:39.724Z
Reserved: 2024-12-10T15:33:57.416Z
Link: CVE-2024-55662
Updated: 2024-12-13T14:59:35.343Z
Status : Analyzed
Published: 2024-12-12T18:15:27.860
Modified: 2025-04-30T16:03:21.090
Link: CVE-2024-55662
No data.
                        OpenCVE Enrichment
                    No data.
 Github GHSA