CVE-2024-31464
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-31464 is a vulnerability affecting XWiki Platform, a generic wiki solution. In versions prior to 14.10.19, 15.5.4, and 15.9-rc1, the deletion of an object storing a password allows access to the password hash using the diff feature. This is particularly concerning for user profiles, where an attacker with editing rights (typically limited to Admins) can exploit this vulnerability. The risk extends to extensions using xobjects for password storage, depending on their access rights. The extent of exploitation cannot be definitively determined, but it requires Admin privileges. To mitigate the risk, administrators should ensure proper protection of user pages, restricting editing rights to Admins and profile owners. XWiki users are advised to change passwords on potentially affected pages and consider upgrading to a secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xwiki
Affected Vendors
- xwiki