CVE-2025-24893
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-24893 is a critical vulnerability affecting the XWiki Platform. An unauthenticated attacker can exploit this issue by sending a malicious request to the `SolrSearch` feature, leading to arbitrary remote code execution. This vulnerability poses a significant threat to the confidentiality, integrity, and availability of the entire XWiki installation. To identify the vulnerability, an attacker can check for output containing "Hello from search text:42" in an RSS feed. XWiki versions 15.10.11, 16.4.1, and 16.5.0RC1 have been patched. Users are strongly advised to upgrade as soon as possible. Alternatively, users who cannot upgrade can edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` to change the content type to `application/xml`.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.