CVE-2024-42489
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vulnerability is fixed in 1.10.1.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 1.06%
- CWE
- CWE-74
- Published
- 2024-08-12
- Last modified
- 2026-03-13
Affected products
- xwikisas xwiki-pro-macros
Weakness type
Related vulnerabilities
- CVE-2026-87925 — Rizwan17 inventory-management-system manage.php storeCustomerOrderInvoice sql injection
- CVE-2026-87921 — Rizwan17 inventory-management-system manage.php update_record sql injection
- CVE-2026-87572 — Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had...
- CVE-2026-86675 — itsourcecode Sales and Inventory System us_edit.php sql injection
- CVE-2026-65669 — Microsoft SQL Server Elevation of Privilege Vulnerability
- CVE-2026-86667 — aircheng-org iWebShop-5 member.php member_list sql injection
- CVE-2026-86518 — code-projects Student Crud Operation edit.php sql injection
- CVE-2026-86517 — itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection