CRITICAL🇵🇱 Wersja polska

CVE-2025-55748

CVSS 9.3v4.0pub. 2025-09-03upd. 2025-09-10

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using URLs such as `http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false`. This is fixed in version 16.10.7.

🤖 AI Analysis
How it works

The jsx (JavaScript Extension) and sx (Skin Extension) endpoints support a resource parameter that allows specifying a resource to be loaded. The lack of proper path validation and sanitization in this parameter allows an attacker to use path traversal sequences (e.g., ../../) to escape the allowed directory and point to any file on the server. A sample request exploiting the vulnerability looks as follows: /bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false. The attack requires no authentication or user interaction.

Impact

An attacker can read the contents of sensitive server configuration files without authentication, including the xwiki.cfg file located in the WEB-INF directory, which may lead to disclosure of passwords, keys, and other confidential XWiki installation configuration data.

Mitigation & patch

XWiki Platform should be updated to version 16.10.7, in which the issue has been fixed. Patch details are available in the vendor's references (GitHub Security Advisory GHSA-m63c-3rmg-r2cf and commit 9e7b4c03).

Who is affected

XWiki Platform in versions from 4.2-milestone-2 to 16.10.6 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Xwiki

    APP
    Xwiki
    4.24.3 – 16.10.7 (excl.)17.0.0 – 17.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2025-24893CRITICAL9.8⚠ KEVPL ✓same product

XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch

CVE-2025-55747CRITICAL9.3PL ✓same product

XWiki Platform: ujawnienie plików konfiguracyjnych przez webjars API (path traversal)

CVE-2025-32429CRITICAL9.3PL ✓same product

SQL Injection w XWiki Platform via parametr sort w getdeleteddocuments.vm

CVE-2025-53836CRITICAL9.9PL ✓same product

XWiki Rendering: bypass trybu restricted przez zagnieżdżone makra

CVE-2025-53835CRITICAL9.0PL ✓same product

XWiki Rendering: XSS przez składnię xdom+xml/current w XHTML