CVE-2024-31982 is a critical remote code execution (RCE) vulnerability affecting XWiki Platform versions 2.4-milestone-1 through 4.10.19, 15.5.3, and 15.10-rc-1. It allows any visitor or user to execute arbitrary code via the database search function, compromising confidentiality, integrity, and availability. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.9427, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. While not yet in CISA's KEV catalog, Nuclei templates exist for exploitation, and it has garnered significant community discussion, indicating high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4, < 14.10.20CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.5.4CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 15.6, < 15.10CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.