Логотип exploitDog
bind:CVE-2024-21650
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-21650

Количество 3

Количество 3

nvd логотип

CVE-2024-21650

около 2 лет назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.

CVSS3: 10
EPSS: Критический
github логотип

GHSA-rj7p-xjv7-7229

около 2 лет назад

XWiki Remote Code Execution Vulnerability via User Registration

CVSS3: 10
EPSS: Критический
fstec логотип

BDU:2024-00970

около 2 лет назад

Уязвимость функции регистрации пользователей платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-21650

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.

CVSS3: 10
93%
Критический
около 2 лет назад
github логотип
GHSA-rj7p-xjv7-7229

XWiki Remote Code Execution Vulnerability via User Registration

CVSS3: 10
93%
Критический
около 2 лет назад
fstec логотип
BDU:2024-00970

Уязвимость функции регистрации пользователей платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
93%
Критический
около 2 лет назад

Уязвимостей на страницу