Improper Handling of Insufficient Privileges in XWiki platform - CVE-2024-21648
Published: January 8, 2024 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to gain rights they do not have anymore.
The vulnerability exists due to improper handling of insufficient privileges in the rollback action when performing a page rollback. A remote user can roll back a page to a previous version to gain rights they do not have anymore.
User interaction is required.