CVE-2025-32430

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflected XSS vulnerabilities, allowing an attacker to execute malicious JavaScript code in the context of the victim's session by getting the victim to visit an attacker-controlled URL. This permits the attacker to perform arbitrary actions using the permissions of the victim. This issue is fixed in versions 16.4.8, 16.10.6 and 17.3.0-rc-1. To workaround the issue, manually patch the WAR with the same changes as the original patch.
CVSS

No CVSS.

Configurations

No configuration.

History

06 Aug 2025, 21:15

Type Values Removed Values Added
References () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-m9x4-w7p9-mxhx - () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-m9x4-w7p9-mxhx -

06 Aug 2025, 20:23

Type Values Removed Values Added
Summary
  • (es) XWiki Platform es una plataforma wiki genérica que ofrece servicios de ejecución para aplicaciones desarrolladas sobre ella. En las versiones 4.2-milestone-3 a 16.4.7, 16.5.0-rc-1 a 16.10.5 y 17.0.0-rc-1 a 17.2.2, dos plantillas contienen vulnerabilidades XSS reflejadas, lo que permite a un atacante ejecutar código JavaScript malicioso en la sesión de la víctima al obligarla a visitar una URL controlada por el atacante. Esto permite al atacante realizar acciones arbitrarias utilizando los permisos de la víctima. Este problema se ha corregido en las versiones 16.4.8, 16.10.6 y 17.3.0-rc-1. Para solucionarlo, parchee manualmente el WAR con los mismos cambios que el parche original.

06 Aug 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 00:15

Updated : 2025-08-06 21:15


NVD link : CVE-2025-32430

Mitre link : CVE-2025-32430

CVE.ORG link : CVE-2025-32430


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')