CVE-2024-21650
XWiki Remote Code Execution vulnerability via user registration
In short
XWiki allows attackers to run malicious code during user registration by entering specially crafted text in name fields. This is critical because anyone can register and take over the system if registration is open to guests.
Technical detail
CWE-95 (Code Injection) vulnerability in XWiki's user registration endpoint allows arbitrary code execution via unsanitized input in first name and last name parameters. Exploitation requires only network access to an instance with guest registration enabled; the injected payload is executed with application privileges, enabling complete system compromise.
Summary generated and translated by AI from the official description.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
xwiki · xwiki-platformWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →