XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2024-31986 - Vulnerability Database

XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2024-31986

High
Reference: CVE-2024-31986
Title: XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability
Overview:

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19 15.5.4 and 15.10-rc-1 by creating a document with a special crafted documented reference and an XWiki.SchedulerJobClass XObject it is possible to execute arbitrary code on the server whenever an admin visits the scheduler page or the scheduler page is referenced e.g. via an image in a comment on a page in the wiki. The vulnerability has been fixed in XWiki 14.10.19 15.5.5 and 15.9. As a workaround apply the patch manually by modifying the Scheduler.WebHome page.