S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-31982 Scanner

CVE-2024-31982 Scanner - Remote Code Execution (RCE) vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-31982
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code execution for any visitor of a public wiki or user of a closed wiki as the database search is by default accessible for all users. This impacts the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1. As a workaround, one may manually apply the patch to the page `Main.DatabaseSearch`. Alternatively, unless database search is explicitly used by users, this page can be deleted as this is not the default search interface of XWiki.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
xwiki-platformby xwiki
>= 2.4-milestone-1, < 14.10.20
xwiki-platformby xwiki
AFFECTED< 14.10.20SAFE ✓≥ 14.10.20
Updated Aug 22, 2026View on NVD →
Detail

XWiki is a comprehensive open-source wiki software application primarily used in corporate environments for collaboration and knowledge sharing. It is designed for creating and managing complex wiki ecosystems and supports features such as applications within the wiki, advanced user rights management, and integration capabilities with third-party services. Enterprises and large organizations commonly use it to facilitate document management and collaborative applications across multiple departments. Due to its open-source nature, developers frequently customize and enhance the base functionalities to meet specific organizational needs. The platform's flexibility allows for tailored solutions that support various business processes, thereby improving internal communication and efficiency. However, rigorous security assessments are necessary due to the potential introduction of vulnerabilities through customizations.

Remote Code Execution (RCE) vulnerabilities allow attackers to execute arbitrary code on a remote system, potentially leading to full system compromise. This particular vulnerability in XWiki's database search functionality allows for such remote code execution, putting the entire application's confidentiality, integrity, and availability at risk. Attackers can leverage this flaw to run malicious scripts and commands on the server, bypassing authentication restrictions. These vulnerabilities are highly critical as they can be exploited remotely over the network without needing any user interaction or authentication. Effective security controls and prompt patching are essential to mitigate the risks associated with such vulnerabilities.

The vulnerability is rooted in the way XWiki's database search functionality processes certain search text inputs without appropriate sanitation or access control. By injecting specifically crafted payloads into the search text parameter, attackers can execute remote Groovy script commands on the server. This security gap exists in versions prior to 4.10.20, enabling malicious actors to escalate their privileges or execute commands in the context of the application host. As the database search feature is, by default, accessible to all users, the attack surface is considerably broad, making unpatched systems particularly vulnerable. Security patches that address this flaw involve applying updates that restrict the execution of untrusted code in the search functionality.

When exploited, this vulnerability can have severe consequences, including unauthorized access to sensitive information, data manipulation, and potentially a full takeover of the XWiki environment. Compromised systems could serve as launching points for further attacks on internal networks or be leveraged to extract confidential data. Additionally, attackers may modify or delete information within the wiki, disrupt business operations, and cause significant reputational and financial damage. Organizations running vulnerable versions of XWiki are advised to implement robust monitoring systems to detect unauthorized activities and apply necessary security patches immediately.

REFERENCES

Solution Advice
  • Update XWiki to version 4.10.20, 15.5.4, or 15.10-rc-1 to apply patches that fix this vulnerability.
  • Enable rigorous access control on the database search functionality to prevent unauthorized exploitation.
  • Introduce input validation and sanitation mechanisms to filter out malicious payloads within search queries.
  • Regularly review and audit server logs for unusual activity related to the search functionality.
  • Consider removing the 'Main.DatabaseSearch' page if it is not explicitly needed for the operation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.