Логотип exploitDog
bind:CVE-2024-55879
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-55879

Количество 2

Количество 2

nvd логотип

CVE-2024-55879

около 1 года назад

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.9 and 16.3.0. No known workarounds are available except upgrading.

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-r279-47wg-chpr

около 1 года назад

XWiki allows RCE from script right in configurable sections

CVSS3: 9.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-55879

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.9 and 16.3.0. No known workarounds are available except upgrading.

CVSS3: 9.1
20%
Средний
около 1 года назад
github логотип
GHSA-r279-47wg-chpr

XWiki allows RCE from script right in configurable sections

CVSS3: 9.1
20%
Средний
около 1 года назад

Уязвимостей на страницу