PT-2025-30912 · Xwiki · Xwiki

Thomas Mortagne

·

Publicado

2025-07-25

·

Atualizado

2025-07-26

·

CVE-2025-54385

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xWiki versions prior to 16.10.6 xWiki versions prior to 17.3.0-rc-1
Description The application allows execution of arbitrary SQL queries in Oracle databases using functions like DBMS XMLGEN or DBMS XMLQUERY. The XWiki#searchDocuments API does not sanitize queries, and Hibernate allows the use of native functions within HQL queries.
Recommendations Upgrade to xWiki version 16.10.6 or later. Upgrade to xWiki version 17.3.0-rc-1 or later.

Exploit

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-13439
CVE-2025-54385
GHSA-P9QM-P942-Q3W5

Produtos afetados

Xwiki