PT-2025-47412 · Xwiki · Xwiki Admin Tools
Published
2025-11-18
·
Updated
2025-11-19
·
CVE-2025-54990
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki AdminTools versions prior to 1.1
Description
XWiki AdminTools provides administrative tools for managing a running XWiki instance. Prior to version 1.1, users lacking administrator privileges could access the
AdminTools.SpammedPages page. While no data was visible to non-administrator users, the page remained accessible. The issue concerns access rights for the AdminTools.SpammedPages page, where view rights were not restricted to administrator users.Recommendations
Update to version 1.1 or later.
Set the view rights for the
AdminTools space to be only available for the XWikiAdminGroup.Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Admin Tools