Логотип exploitDog
bind:CVE-2024-31987
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-31987

Количество 2

Количество 2

nvd логотип

CVE-2024-31987

почти 2 года назад

XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading.

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-cv55-v6rw-7r5v

почти 2 года назад

XWiki Platform remote code execution from account via custom skins support

CVSS3: 9.9
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-31987

XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading.

CVSS3: 9.9
34%
Средний
почти 2 года назад
github логотип
GHSA-cv55-v6rw-7r5v

XWiki Platform remote code execution from account via custom skins support

CVSS3: 9.9
34%
Средний
почти 2 года назад

Уязвимостей на страницу