PT-2025-25438 · Xwiki · Xwiki

Michitux

·

Published

2024-12-06

·

Updated

2025-06-16

·

CVE-2025-49586

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 16.4.7 XWiki versions prior to 16.10.3 XWiki versions prior to 17.0.0
Description The issue allows any XWiki user with edit rights on at least one App Within Minutes application to obtain programming rights and perform remote code execution by editing the application.
Recommendations For versions prior to 16.4.7, update to version 16.4.7 or later. For versions prior to 16.10.3, update to version 16.10.3 or later. For versions prior to 17.0.0, update to version 17.0.0 or later.

Exploit

Fix

RCE

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-11352
CVE-2025-49586
GHSA-JP4X-W9CJ-97Q7

Affected Products

Xwiki