SQL injection in XWiki platform - CVE-2024-55663

 

SQL injection in XWiki platform - CVE-2024-55663

Published: December 12, 2024 / Updated: April 9, 2026


Vulnerability identifier: #VU125589
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-55663
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and modify database contents.

The vulnerability exists due to SQL injection in getdocument.vm when processing the request.sort parameter. A remote attacker can send a specially crafted request to disclose sensitive information and modify database contents.

Depending on the database backend, exploitation may allow access to confidential data such as password hashes and execution of UPDATE, INSERT, or DELETE queries.


Affected software

XWiki platform

How to mitigate CVE-2024-55663

Install security update from vendor's website.

XWiki platform - addressed in versions 13.10.5, 14.3 rc-1

External References

Related Security Bulletins