PT-2025-40900 · Xwiki · Xwiki
Thomas Mortagne
·
Published
2025-10-06
·
Updated
2025-10-23
·
CVE-2025-49594
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
XWiki versions 2.17.1 through 2.18.1
Description
XWiki OpenID Connect (OIDC) contains tools for manipulating the OpenID Connect protocol. Individuals with VIEW access to a user profile can generate a token for that user in versions prior to 2.18.2. If the XWiki instance permits token authentication, this allows authentication as any user, as user profiles are often viewable by other registered users.
Recommendations
Upgrade to version 2.18.2.
Disable token access.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki