CVSS v3
8.8
HIGH
EPSS Score
33.7 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading.
Technical details
- Published
- 2024-04-10
Frequently asked questions
What is CVE-2024-31987?
XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading.
Is CVE-2024-31987 actively exploited?
Active exploitation of CVE-2024-31987 has not been confirmed. The EPSS score is 33.7%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2024-31987?
CVE-2024-31987 has a CVSS v3 base score of 8.8 (HIGH severity).
Is CVE-2024-31987 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 30 free checks/month · Free API key
Other 2024 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).