Eval Injection in XWiki platform - CVE-2024-21650
Published: January 8, 2024 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the user registration feature when processing user-supplied "first name" or "last name" fields during registration. A remote attacker can submit crafted registration data to execute arbitrary code.
Only installations that have user registration enabled for guests are vulnerable.