CVE-2024-43400
moderate-risk
Published 2024-08-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.
Do I need to act?
~
5.7% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.0/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (3)
44
/ 100
moderate-risk
Severity
30/34 · Critical
Exploitability
9/34 · Low
Exposure
5/34 · Minimal