XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using URLs such as `http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false`. This is fixed in version 16.10.7.
The jsx (JavaScript Extension) and sx (Skin Extension) endpoints support a resource parameter that allows specifying a resource to be loaded. The lack of proper path validation and sanitization in this parameter allows an attacker to use path traversal sequences (e.g., ../../) to escape the allowed directory and point to any file on the server. A sample request exploiting the vulnerability looks as follows: /bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false. The attack requires no authentication or user interaction.
An attacker can read the contents of sensitive server configuration files without authentication, including the xwiki.cfg file located in the WEB-INF directory, which may lead to disclosure of passwords, keys, and other confidential XWiki installation configuration data.
XWiki Platform should be updated to version 16.10.7, in which the issue has been fixed. Patch details are available in the vendor's references (GitHub Security Advisory GHSA-m63c-3rmg-r2cf and commit 9e7b4c03).
XWiki Platform in versions from 4.2-milestone-2 to 16.10.6 inclusive.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XXwiki
APPXwiki4.24.3 – 16.10.7 (excl.)17.0.0 – 17.3.0
Related vulnerabilities
XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch
XWiki Platform: ujawnienie plików konfiguracyjnych przez webjars API (path traversal)
SQL Injection w XWiki Platform via parametr sort w getdeleteddocuments.vm
XWiki Rendering: bypass trybu restricted przez zagnieżdżone makra
XWiki Rendering: XSS przez składnię xdom+xml/current w XHTML