Loading
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vulnerability is fixed in 1.10.1.
Use CWE-74, Xwiki vendor hub and Pro Macros product page to widen CVE-2024-42489 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-55728, CVE-2025-55727 and CVE-2025-65036 for nearby disclosures in the same product family.