Cross-site request forgery in XWiki platform - CVE-2024-31985

 

Cross-site request forgery in XWiki platform - CVE-2024-31985

Published: April 10, 2024 / Updated: May 5, 2026


Vulnerability identifier: #VU129908
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31985
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform unauthorized job scheduling actions.

The vulnerability exists due to cross-site request forgery (CSRF) in the job scheduler page when handling crafted requests to schedule, trigger, or unschedule existing jobs. A remote attacker can embed a predictable URL in content to perform unauthorized job scheduling actions.

User interaction is required, and the victim must visit the job scheduler page with administrative rights.


Affected software

XWiki platform

How to mitigate CVE-2024-31985

Install security update from vendor's website.

XWiki platform - addressed in versions 14.10.19, 15.5.4, 15.9

External References

Related Security Bulletins