Cross-site request forgery in XWiki platform - CVE-2024-31985
Published: April 10, 2024 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote attacker to perform unauthorized job scheduling actions.
The vulnerability exists due to cross-site request forgery (CSRF) in the job scheduler page when handling crafted requests to schedule, trigger, or unschedule existing jobs. A remote attacker can embed a predictable URL in content to perform unauthorized job scheduling actions.
User interaction is required, and the victim must visit the job scheduler page with administrative rights.