PT-2025-34071 · Xwiki · Xwiki
Malcxlmj
·
Published
2025-08-16
·
Updated
2025-11-12
·
CVE-2025-51990
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
XWiki versions through 17.3.0
Description:
XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specifically under the Presentation section of the Global Preferences panel. An authenticated administrator can inject arbitrary JavaScript payloads into the HTTP Meta Info, Footer Copyright, and Footer Version fields. These inputs are stored and subsequently rendered without proper output encoding or sanitization on public-facing pages, leading to persistent execution of injected scripts in the browser context of any visitor, including both authenticated and unauthenticated users. Successful exploitation can lead to session hijacking, credential theft, unauthorized actions, or further compromise of the application through client-side attacks.
Recommendations:
XWiki version 17.4.0 and later should be used.
As a temporary workaround, restrict access to the Administration interface to minimize the risk of exploitation.
Avoid using JavaScript payloads in the HTTP Meta Info, Footer Copyright, and Footer Version fields.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki