XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Scheduler.WebHome` in a subwiki. Then, click on any operation (*e.g.,* Trigger) on any job. If the operation is successful, then the instance is vulnerable. This has been patched in XWiki 15.10.9 and 16.3.0. As a workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on `Scheduler.WebPreferences` to match the patch.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-3461 XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Scheduler.WebHome` in a subwiki. Then, click on any operation (*e.g.,* Trigger) on any job. If the operation is successful, then the instance is vulnerable. This has been patched in XWiki 15.10.9 and 16.3.0. As a workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on `Scheduler.WebPreferences` to match the patch.
Github GHSA Github GHSA GHSA-cwq6-mjmx-47p6 XWiki's scheduler in subwiki allows scheduling operations for any main wiki user
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki
Xwiki xwiki
CPEs cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:-:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:1.2:-:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:1.2:milestone2:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:1.2:rc1:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:1.2:rc2:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:1.2:rc3:*:*:*:*:*:*
Vendors & Products Xwiki
Xwiki xwiki
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Fri, 13 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
Description XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Scheduler.WebHome` in a subwiki. Then, click on any operation (*e.g.,* Trigger) on any job. If the operation is successful, then the instance is vulnerable. This has been patched in XWiki 15.10.9 and 16.3.0. As a workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on `Scheduler.WebPreferences` to match the patch.
Title XWiki's scheduler in subwiki allows scheduling operations for any main wiki user
Weaknesses CWE-862
References
Metrics cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-12-13T14:55:19.672Z

Reserved: 2024-12-11T15:46:36.421Z

Link: CVE-2024-55876

cve-icon Vulnrichment

Updated: 2024-12-13T14:52:11.232Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-12T19:15:14.140

Modified: 2025-04-30T16:02:40.777

Link: CVE-2024-55876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.