CVE-2024-31997

EUVD-2024-1179
XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the user's own profile can create UI extensions. This allows remote code execution and thereby impacts the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.19, 15.5.4 and 15.9-RC1. No known workarounds are available.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
xwikixwiki
𝑥
< 14.10.19
xwikixwiki
15.0 ≤
𝑥
< 15.5.4
xwikixwiki
15.6 ≤
𝑥
< 15.9
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
xwikixwiki
𝑥
< 14.10.19
ADP
xwikixwiki
15.0-rc-1 ≤
𝑥
< 15.5.4
ADP
xwikixwiki
15.6-rc-1 ≤
𝑥
< 15.9-rc-1
ADP