CVE-2024-56158: XWiki allows SQL injection in query endpoint of REST API with Oracle
N/A
CVSS Score
Basic Information
CVE ID
GHSA ID
EPSS Score
0.20491%
CWE
Published
6/12/2025
Updated
6/12/2025
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.xwiki.platform:xwiki-platform-oldcore | maven | >= 1.0, < 15.10.16 | 15.10.16 |
| org.xwiki.platform:xwiki-platform-oldcore | maven | >= 16.0.0-rc-1, < 16.4.7 | 16.4.7 |
| org.xwiki.platform:xwiki-platform-oldcore | maven | >= 16.5.0-rc-1, < 16.10.2 | 16.10.2 |