CVSS 3.1 Score 9.6 of 10 (high)


Published Apr 10, 2024
Updated: Apr 11, 2024
CWE ID 352


CVE-2024-31988 is a critical vulnerability that affects XWiki Platform versions 13.9-rc-1 and prior to 4.10.19, 15.5.4, and 15.10-rc-1. This vulnerability allows arbitrary remote code execution when the realtime editor is installed in XWiki, with the interaction of an admin user with programming rights. An attacker can exploit this by tricking an admin user into visiting a crafted URL or viewing an image containing a malicious URL in a comment, which then executes arbitrary XWiki syntax including scripting macros with Groovy or Python code. The impact of this vulnerability is significant, compromising the confidentiality, integrity, and availability of the entire XWiki installation. To remediate this issue, users should update to XWiki versions 14.10.19, 15.5.4, or 15.9 as they include patches for this vulnerability. Alternatively, users can manually apply a patch to the RTFrontend.ConvertHTML component but this may cause issues with synchronization processes in the realtime editor.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-31988 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options