CVE-2024-42489 is a critical remote code execution (RCE) vulnerability affecting XWiki Pro Macros, specifically due to missing escaping in macros like Viewpdf and Viewppt. An attacker with view rights on the CKEditor.HTMLConverter page, or edit/comment rights on any page, can exploit this flaw to execute arbitrary code. The vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and there's minimal community discussion or media coverage, the high EPSS score suggests a significant likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0, < 1.10.1CPE matchmatch criteria | cpe:2.3:a:xwiki:pro_macros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.