CVE-2024-31988
CVSS 3.1 Score 9.6 of 10 (high)
Details
Summary
CVE-2024-31988 is a critical vulnerability that affects XWiki Platform versions 13.9-rc-1 and prior to 4.10.19, 15.5.4, and 15.10-rc-1. This vulnerability allows arbitrary remote code execution when the realtime editor is installed in XWiki, with the interaction of an admin user with programming rights. An attacker can exploit this by tricking an admin user into visiting a crafted URL or viewing an image containing a malicious URL in a comment, which then executes arbitrary XWiki syntax including scripting macros with Groovy or Python code. The impact of this vulnerability is significant, compromising the confidentiality, integrity, and availability of the entire XWiki installation. To remediate this issue, users should update to XWiki versions 14.10.19, 15.5.4, or 15.9 as they include patches for this vulnerability. Alternatively, users can manually apply a patch to the `RTFrontend.ConvertHTML` component but this may cause issues with synchronization processes in the realtime editor.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions