CRITICAL🇵🇱 Wersja polska

CVE-2025-32429

CVSS 9.3v4.0pub. 2025-07-24upd. 2025-09-03

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.

🤖 AI Analysis
How it works

The sort parameter passed to the getdeleteddocuments.vm template is inserted directly without validation or sanitization as a value of the ORDER BY clause in an SQL query. An attacker can send a crafted HTTP request with an appropriately modified sort parameter value, thereby injecting arbitrary SQL code. The attack requires no authentication or user interaction.

Impact

An attacker can read, modify, or delete data stored in the XWiki database, including potentially gaining access to sensitive information such as user data, session tokens, or wiki content.

Mitigation & patch

Update XWiki Platform to version 16.10.6 or 17.3.0-rc-1 (and newer), in which the vulnerability has been fixed. Patches are available in the project repository on GitHub (commits dfd0744e9c18d24ac66a0d261dc6cafd1c209101 and f502b5d5fd36284a50890ad26d168b7d8dc80bd3).

Who is affected

XWiki Platform in versions from 9.4-rc-1 to 16.10.5 and from 17.0.0-rc-1 to 17.2.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Xwiki

    APP
    Xwiki
    9.4 – 16.10.6 (excl.)17.0.0 – 17.2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-24893CRITICAL9.8⚠ KEVPL ✓same product

XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch

CVE-2025-55748CRITICAL9.3PL ✓same product

XWiki Platform — path traversal umożliwia odczyt plików konfiguracyjnych

CVE-2025-55747CRITICAL9.3PL ✓same product

XWiki Platform: ujawnienie plików konfiguracyjnych przez webjars API (path traversal)

CVE-2025-53836CRITICAL9.9PL ✓same product

XWiki Rendering: bypass trybu restricted przez zagnieżdżone makra

CVE-2025-53835CRITICAL9.0PL ✓same product

XWiki Rendering: XSS przez składnię xdom+xml/current w XHTML