CVE-2024-31983

CRITICAL

XWiki Platform <4.10.20, 15.5.4, 15.10-rc-1 - RCE

Title source: llm
STIX 2.1

Description

XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights that are normally required for authoring translations (script right for user-scope translations, wiki admin for translations on the wiki). Starting in version 4.3-milestone-2 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, this can be exploited for remote code execution if the translation value is not properly escaped where it is used. This has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1. As a workaround, one may restrict edit rights on documents that contain translations.

Scores

CVSS v3 9.9
EPSS 0.2330
EPSS Percentile 96.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (3)
org.xwiki.platform/xwiki-platform-localization-source-wiki 4.3-milestone-2 - 14.10.20Maven
xwiki/xwiki 4.3 (3 CPE variants)
xwiki/xwiki 4.3.1 - 14.10.20
Published Apr 10, 2024
Tracked Since Feb 18, 2026