Eval Injection in XWiki platform - CVE-2024-21650

 

Eval Injection in XWiki platform - CVE-2024-21650

Published: January 8, 2024 / Updated: May 5, 2026


Vulnerability identifier: #VU129910
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-21650
CWE-ID: CWE-95
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
XWiki platform
Software vendor:
XWiki

Description

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the user registration feature when processing user-supplied "first name" or "last name" fields during registration. A remote attacker can submit crafted registration data to execute arbitrary code.

Only installations that have user registration enabled for guests are vulnerable.


Remediation

Install security update from vendor's website.

External links