Missing Authorization in XWiki platform - CVE-2024-31983
Published: April 10, 2024 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to missing authorization in wiki translation editing in multilingual wikis when editing translations. A remote user can modify a translation value to inject script code and execute arbitrary code.
This affects translations that can be edited by users with edit right without the normally required script right for user-scope translations or wiki admin rights for wiki translations.