GHSA-r279-47wg-chpr
CRITICALCVE-2024-55879Any user with script rights can perform arbitrary remote code execution by adding instances of XWiki.ConfigurableClass to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation.
- Affected
- >= 2.3, < 15.10.9, >= 16.0.0-rc-1, < 16.3.0
- Fixed in
- 15.10.9
- Weakness
- CWE-862
- Published
- 2024-12-12
- Source
- github