First published: Mon Aug 12 2024(Updated: )
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vulnerability is fixed in 1.10.1.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xwiki Pro Macros | >=1.0<1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42489 has been classified with a high severity due to potential remote code execution.
To fix CVE-2024-42489, update the Pro Macros to a version above 1.10.1 where the vulnerability is addressed.
Any user with view rights on the CKEditor.HTMLConverter page or edit or comment rights on any page is affected by CVE-2024-42489.
Exploiting CVE-2024-42489 can lead to remote code execution, compromising the security of the affected system.
Pro Macros versions between 1.0 and 1.10.1, inclusive, are vulnerable to CVE-2024-42489.