CRITICAL🇵🇱 Wersja polska

CVE-2025-55747

CVSS 9.3v4.0pub. 2025-09-03upd. 2025-09-10

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API. This is fixed in version 16.10.7.

🤖 AI Analysis
How it works

The flaw classified as CWE-23 (path traversal) consists of improper path validation in the webjars API of the XWiki platform. An attacker can construct an appropriate HTTP request to this API to escape the allowed directory and read application configuration files. The vulnerability is accessible remotely without the need for an account in the system.

Impact

An attacker can gain unauthorized access to XWiki configuration files, which may contain credentials, API keys, database connection parameters, and other sensitive configuration information. Disclosure of this data can lead to further system compromise.

Mitigation & patch

XWiki Platform should be updated to version 16.10.7 or later, in which the vulnerability has been fixed. The patch is available in the project's GitHub repository (commit 9e7b4c03f2143978d891109a17159f73d4cdd318).

Who is affected

XWiki Platform in versions from 6.1-milestone-2 to 16.10.6 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Xwiki

    APP
    Xwiki
    6.16.2 – 16.10.7 (excl.)17.0.0 – 17.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-24893CRITICAL9.8⚠ KEVPL ✓same product

XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch

CVE-2025-55748CRITICAL9.3PL ✓same product

XWiki Platform — path traversal umożliwia odczyt plików konfiguracyjnych

CVE-2025-32429CRITICAL9.3PL ✓same product

SQL Injection w XWiki Platform via parametr sort w getdeleteddocuments.vm

CVE-2025-53836CRITICAL9.9PL ✓same product

XWiki Rendering: bypass trybu restricted przez zagnieżdżone makra

CVE-2025-53835CRITICAL9.0PL ✓same product

XWiki Rendering: XSS przez składnię xdom+xml/current w XHTML