CVE-2025-55748
🟡 Monitoruj
Niezabezpieczone punkty końcowe w XWiki umożliwiają dostęp do plików konfiguracyjnych.
CVSS
7.5
EPSS
1.8%
Exploit
none
Vendor
xwiki
Opis źródłowy (NVD)
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using URLs such as `http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false`. This is fixed in version 16.10.7.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.8% |
| Opublikowano (NVD) | 2025-09-03 21:15:32 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://github.com/xwiki/xwiki-platform/commit/9e7b4c03f2143978d891109a17159f73d4cdd318#diff-ee78930a9ac5ea586179fe8ab88a5fd58e369d175927d1e88a0b4dbc3ebcbf1eR62 ([email protected]) [Patch]
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-m63c-3rmg-r2cf ([email protected]) [Vendor Advisory]
- https://jira.xwiki.org/browse/XWIKI-23109 ([email protected]) [Issue Tracking, Vendor Advisory]