CVE-2024-31988

CVSS 3.1 Score 9.6 of 10 (high)

Details

Published Apr 10, 2024
Updated: Apr 11, 2024
CWE ID 352

Summary

CVE-2024-31988 is a critical vulnerability that affects XWiki Platform versions 13.9-rc-1 and prior to 4.10.19, 15.5.4, and 15.10-rc-1. This vulnerability allows arbitrary remote code execution when the realtime editor is installed in XWiki, with the interaction of an admin user with programming rights. An attacker can exploit this by tricking an admin user into visiting a crafted URL or viewing an image containing a malicious URL in a comment, which then executes arbitrary XWiki syntax including scripting macros with Groovy or Python code. The impact of this vulnerability is significant, compromising the confidentiality, integrity, and availability of the entire XWiki installation. To remediate this issue, users should update to XWiki versions 14.10.19, 15.5.4, or 15.9 as they include patches for this vulnerability. Alternatively, users can manually apply a patch to the `RTFrontend.ConvertHTML` component but this may cause issues with synchronization processes in the realtime editor.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-31988 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions