CVE-2025-23025

CVSS 3.1 Score 9 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 862

Summary

CVE-2025-23025 affects the XWiki Platform, a wiki solution with runtime services for applications. The Realtime WYSIWYG Editor extension, which was previously experimental and not recommended, has become enabled by default and can lead to a vulnerability. Users with edit rights can join realtime editing sessions and insert script rendering macros that are executed for those with script or programming rights. These scripts can potentially be used to gain additional access rights. This vulnerability has been patched in XWiki 15.10.2, 16.4.1, and 16.6.0-rc-1. To mitigate the risk, users unable to upgrade can disable the realtime WYSIWYG editing plugin or uninstall the Realtime WYSIWYG Editor extension.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share