PT-2025-25434 · Xwiki · Xwiki

Michael Hamann

·

Published

2024-08-30

·

Updated

2025-06-13

·

CVE-2025-49583

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 15.10.16 XWiki versions prior to 16.4.7 XWiki versions prior to 16.10.2
Description The issue affects XWiki, a generic wiki platform. It occurs when a user without script right creates a document with an XWiki.Notifications.Code.NotificationEmailRendererClass object. If an admin later edits and saves that document, the email templates in this object will be used for notifications. Although no malicious code can be executed due to the existing generic analyzer warning admins before editing Velocity code, the main impact could be to send spam, such as phishing links to other users, or to hide notifications about other attacks.
Recommendations For versions prior to 15.10.16, update to version 15.10.16 or later. For versions prior to 16.4.7, update to version 16.4.7 or later. For versions prior to 16.10.2, update to version 16.10.2 or later. As a temporary workaround, consider restricting access to documents with XWiki.Notifications.Code.NotificationEmailRendererClass objects until the issue is resolved. Avoid using the XWiki.Notifications.Code.NotificationEmailRendererClass object in documents until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-06832
CVE-2025-49583
GHSA-FF6V-W58F-V97W

Affected Products

Xwiki