Логотип exploitDog
bind:CVE-2024-31996
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-31996

Количество 3

Количество 3

nvd логотип

CVE-2024-31996

почти 2 года назад

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki syntax injection and thereby remote code execution. The vulnerability has been fixed in XWiki 14.10.19, 15.5.5, and 15.9 RC1. Apart from upgrading, there is no generic workaround. However, replacing `$escapetool.html` by `$escapetool.xml` in XWiki documents fixes the vulnerability. In a standard XWiki installation, the maintainers are only aware of the document `Panels.PanelLayoutUpdate` that exposes this vulnerability, patching this document is thus a workaround. Any extension could expose this vulnerability and might thus require patching, too.

CVSS3: 10
EPSS: Средний
github логотип

GHSA-hf43-47q4-fhq5

почти 2 года назад

XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution

CVSS3: 10
EPSS: Средний
fstec логотип

BDU:2025-01581

больше 2 лет назад

Уязвимость набора библиотек XWiki Commons платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-31996

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki syntax injection and thereby remote code execution. The vulnerability has been fixed in XWiki 14.10.19, 15.5.5, and 15.9 RC1. Apart from upgrading, there is no generic workaround. However, replacing `$escapetool.html` by `$escapetool.xml` in XWiki documents fixes the vulnerability. In a standard XWiki installation, the maintainers are only aware of the document `Panels.PanelLayoutUpdate` that exposes this vulnerability, patching this document is thus a workaround. Any extension could expose this vulnerability and might thus require patching, too.

CVSS3: 10
18%
Средний
почти 2 года назад
github логотип
GHSA-hf43-47q4-fhq5

XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution

CVSS3: 10
18%
Средний
почти 2 года назад
fstec логотип
BDU:2025-01581

Уязвимость набора библиотек XWiki Commons платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
18%
Средний
больше 2 лет назад

Уязвимостей на страницу