First published: Thu Dec 19 2024(Updated: )
This vulnerability allows remote attackers to execute arbitrary code on affected installations of XWiki.org XWiki. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Affected Software | Affected Version | How to fix |
---|---|---|
XWiki |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-CAN-23994 has a CVSS rating of 9.8, indicating a critical severity level.
ZDI-CAN-23994 affects installations of XWiki.org XWiki without any authentication requirements.
To fix ZDI-CAN-23994, update your XWiki installation to the latest patched version provided by XWiki.
Yes, ZDI-CAN-23994 can be exploited remotely as it does not require authentication.
ZDI-CAN-23994 allows remote attackers to execute arbitrary code on affected installations.