logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-21650

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-21650

Description:
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.
Last updated date:
01/11/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/11/2024
Reference url to background

https://jira.xwiki.org/browse/XWIKI-21173

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy