Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r279-47wg-chpr | XWiki allows RCE from script right in configurable sections |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki xwiki |
|
| CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* cpe:2.3:a:xwiki:xwiki:*:-:*:*:*:*:*:* |
|
| Vendors & Products |
Xwiki
Xwiki xwiki |
Fri, 13 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Thu, 12 Dec 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.9 and 16.3.0. No known workarounds are available except upgrading. | |
| Title | XWiki allows RCE from script right in configurable sections | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-13T14:54:21.161Z
Reserved: 2024-12-11T15:46:36.421Z
Link: CVE-2024-55879
Updated: 2024-12-13T14:50:10.938Z
Status : Analyzed
Published: 2024-12-12T20:15:21.623
Modified: 2025-04-30T16:01:22.430
Link: CVE-2024-55879
No data.
OpenCVE Enrichment
No data.
Github GHSA