CVE-2024-43401: In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them
Impact
A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time.
Patches
This vulnerability has been patched in XWiki 15.10RC1.
Workarounds
No workaround. It is advised to upgrade to XWiki 15.10+.
References
https://jira.xwiki.org/browse/XWIKI-20331 https://jira.xwiki.org/browse/XWIKI-21311 https://jira.xwiki.org/browse/XWIKI-21481 https://jira.xwiki.org/browse/XWIKI-21482 https://jira.xwiki.org/browse/XWIKI-21483 https://jira.xwiki.org/browse/XWIKI-21484 https://jira.xwiki.org/browse/XWIKI-21485 https://jira.xwiki.org/browse/XWIKI-21486 https://jira.xwiki.org/browse/XWIKI-21487 https://jira.xwiki.org/browse/XWIKI-21488 https://jira.xwiki.org/browse/XWIKI-21489 https://jira.xwiki.org/browse/XWIKI-21490
For more information
If you have any questions or comments about this advisory: Open an issue in Jira XWiki.org Email us at Security Mailing List
Attribution
This vulnerability has been reported on Intigriti by @floerer
Other sources
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43401?
CVE-2024-43401 is considered a high-severity vulnerability due to the potential for exploitation by malicious users.
How do I fix CVE-2024-43401?
To fix CVE-2024-43401, update to a secure version of the affected software beyond version 15.10-rc-1 or apply any available patches.
What software is affected by CVE-2024-43401?
CVE-2024-43401 affects XWiki versions up to and including 15.9, as well as version 15.10-rc-1 of the xwiki-platform-web-templates package.
Who can exploit CVE-2024-43401?
A user without script or programming rights can exploit CVE-2024-43401 by tricking a user with elevated rights to edit content containing a malicious payload.
What is the impact of CVE-2024-43401?
The impact of CVE-2024-43401 is that it allows unauthorized content edits by users with elevated rights, potentially leading to execution of harmful scripts.