Eval Injection in XWiki platform - CVE-2024-31982
Published: April 10, 2024 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the DatabaseSearch feature when processing search text. A remote attacker can send a specially crafted search query to execute arbitrary code.
The database search is by default accessible to all users, including guests on public wiki instances.