XWikiplatform Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2024-55877 - Vulnerability Database

XWikiplatform Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2024-55877

High
Reference: CVE-2024-55877
Title: XWikiplatform Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11 16.4.1 and 16.5.0 any user with an account can perform arbitrary remote code execution by adding instances of XWiki.WikiMacroClass to any page. This compromises the confidentiality integrity and availability of the whole XWiki installation. This vulnerability has been fixed in XWiki 15.10.11 16.4.1 and 16.5.0. It is possible to manually apply the patch to the page XWiki.XWikiSyntaxMacrosList as a workaround.