CVE-2024-55879 is a critical remote code execution vulnerability affecting XWiki Platform versions 2.3 through 15.10.8 and 16.0-rc-1 through 16.2.0. An authenticated user with script rights can exploit this by adding instances of XWiki.ConfigurableClass to any page, leading to complete compromise of confidentiality, integrity, and availability. With a CVSS score of 8.8 (High) and an EPSS score indicating higher exploitability than 95% of CVEs, this vulnerability presents a significant risk. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, but immediate upgrade to XWiki 15.10.9 or 16.3.0 is the only known remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3, < 15.10.9CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 16.0.0, < 16.3.0CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.