PT-2025-47412 · Xwiki · Xwiki Admin Tools

Published

2025-11-18

·

Updated

2025-11-19

·

CVE-2025-54990

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki AdminTools versions prior to 1.1
Description XWiki AdminTools provides administrative tools for managing a running XWiki instance. Prior to version 1.1, users lacking administrator privileges could access the AdminTools.SpammedPages page. While no data was visible to non-administrator users, the page remained accessible. The issue concerns access rights for the AdminTools.SpammedPages page, where view rights were not restricted to administrator users.
Recommendations Update to version 1.1 or later. Set the view rights for the AdminTools space to be only available for the XWikiAdminGroup.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2025-14721
CVE-2025-54990
GHSA-V7R8-8P5C-H4XW

Affected Products

Xwiki Admin Tools