CRITICAL🇵🇱 Wersja polska

CVE-2024-43400

CVSS 9.0v3.1pub. 2024-08-19upd. 2024-08-20

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.

🤖 AI Analysis
How it works

Attacker without special permissions creates a crafted URL pointing to an XWiki page containing arbitrary JavaScript code (XSS). Then, using social engineering techniques, persuades an authenticated user to click on this link. When the page opens, the victim's browser executes the malicious script in the context of the XWiki application, which can lead to session theft, content modification, or further attack propagation.

Impact

Attacker can gain access to sensitive victim session data, modify wiki content, or perform actions on behalf of the attacked user. Due to CVSS 9.0 rating and scope of impact covering confidentiality, integrity, and availability, consequences can be very serious.

Mitigation & patch

XWiki Platform should be updated to version 14.10.21, 15.5.5, 15.10.6, or 16.0.0, in which the vulnerability has been removed. Additionally, user education is recommended regarding recognition of suspicious links and phishing techniques.

Who is affected

XWiki Platform in versions prior to 14.10.21, 15.5.5, 15.10.6, and 16.0.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Xwiki

    APP
    Xwiki
    < 14.10.2115.0 – 15.5.5 (excl.)15.6 – 15.10.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-24893CRITICAL9.8⚠ KEVPL ✓same product

XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch

CVE-2025-55748CRITICAL9.3PL ✓same product

XWiki Platform — path traversal umożliwia odczyt plików konfiguracyjnych

CVE-2025-55747CRITICAL9.3PL ✓same product

XWiki Platform: ujawnienie plików konfiguracyjnych przez webjars API (path traversal)

CVE-2025-32429CRITICAL9.3PL ✓same product

SQL Injection w XWiki Platform via parametr sort w getdeleteddocuments.vm

CVE-2025-53836CRITICAL9.9PL ✓same product

XWiki Rendering: bypass trybu restricted przez zagnieżdżone makra