CVE-2024-21650 is a critical remote code execution (RCE) vulnerability affecting XWiki Platform versions prior to 14.10.17, 15.5.3, and 15.8 RC1. Attackers can exploit this flaw by injecting malicious payloads into the "first name" or "last name" fields during user registration, provided guest registration is enabled. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.9312, this vulnerability allows unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. While there are no known active exploits or Metasploit modules, Nuclei templates exist, and there is some community discussion, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.10.17CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.5.3CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 15.6, <= 15.7CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.