CVE-2025-32968

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 30, 2025
CWE ID 89

Summary

CVE-2025-32968 is a vulnerability affecting XWiki, a popular wiki platform, from versions 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1. This issue allows users with SCRIPT rights to break free from the HQL execution context and perform a blind SQL injection, potentially gaining access to confidential information like password hashes and executing SQL commands on the database backend. While patches have been released in versions 16.10.1, 16.4.6, and 15.10.16, there is no known workaround besides upgrading XWiki. The protection added to the REST API is similar to the one used for complete queries, but it's important to note that some complex queries might now require the author to possess programming rights.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share