XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been fixed in XWiki 17.0.0, 16.4.7, and 16.10.3.
History

Fri, 13 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 13 Jun 2025 18:00:00 +0000

Type Values Removed Values Added
Description XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been fixed in XWiki 17.0.0, 16.4.7, and 16.10.3.
Title XWiki allows remote code execution through preview of XClass changes in AWM editor
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-13T17:47:07.105Z

Updated: 2025-06-13T18:07:37.038Z

Reserved: 2025-06-06T15:44:21.556Z

Link: CVE-2025-49586

cve-icon Vulnrichment

Updated: 2025-06-13T18:07:30.074Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-13T18:15:22.737

Modified: 2025-06-16T12:32:18.840

Link: CVE-2025-49586

cve-icon Redhat

No data.