Code injection in XWiki platform - CVE-2024-55662
Published: December 12, 2024 / Updated: April 9, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in a command in the Extension Repository Application extension sheet when rendering the description of an ExtensionCode.ExtensionClass object. A remote user can add a crafted ExtensionCode.ExtensionClass object with malicious script content to execute arbitrary code.
Only instances where the Extension Repository Application is installed are vulnerable.