Executive Summary

Informations
Name CVE-2024-31988 First vendor Publication 2024-04-10
Vendor Cve Last vendor Modification 2024-04-11

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed in XWiki, it allows arbitrary remote code execution with the interaction of an admin user with programming right. More precisely, by getting an admin user to either visit a crafted URL or to view an image with this URL that could be in a comment, the attacker can get the admin to execute arbitrary XWiki syntax including scripting macros with Groovy or Python code. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.19, 15.5.4 and 15.9. As a workaround, one may update `RTFrontend.ConvertHTML` manually with the patch. This will, however, break some synchronization processes in the realtime editor, so upgrading should be the preferred way on installations where this editor is used.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31988

Sources (Detail)

https://github.com/xwiki/xwiki-platform/commit/4896712ee6483da623f131be2e618f...
https://github.com/xwiki/xwiki-platform/commit/9f8cc88497418750b09ce9fde5d67d...
https://github.com/xwiki/xwiki-platform/commit/d88da4572fb7d4f95e1f54bb0cce33...
https://github.com/xwiki/xwiki-platform/commit/d9f5043da289ff106f08e23576746f...
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-r5vh-gc3r-r24w
https://jira.xwiki.org/browse/XWIKI-21424
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2024-04-11 17:27:27
  • Multiple Updates
2024-04-11 00:27:25
  • First insertion