TROYANOSYVIRUS
Back to CVEs

CVE-2024-38369

CRITICAL
9.9

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the right of its author. This means that any user able to modify the target document can impersonate the author of the content which used the `include` macro. This vulnerability has been patched in XWiki 15.0 RC1 by making the default behavior safe.

CVE Details

CVSS v3.1 Score9.9
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published6/24/2024
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

xwiki:xwiki

Weaknesses (CWE)

CWE-863CWE-863

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.